漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened
Vulnerability Description
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal — while believing the startup-hardened tier guaranteed tamper-resistance. Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded). This issue has been patched in version 1.4.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
不完整的文件
Vulnerability Title
Kerberosmansour Hulumi 服务供应链问题漏洞
Vulnerability Description
Kerberosmansour Hulumi是Kerberosmansour个人开发者的一个面向Pulumi的云基础设施安全工具包。 Kerberosmansour Hulumi 1.4.0之前版本存在服务供应链问题漏洞,该漏洞源于AccountFoundation组件设计问题,可能导致具备S3删除权限的主体删除CloudTrail和Config审计日志。
CVSS Information
N/A
Vulnerability Type
N/A