Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened
Vulnerability Description
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal — while believing the startup-hardened tier guaranteed tamper-resistance. Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded). This issue has been patched in version 1.4.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
不完整的文件
Vulnerability Title
Kerberosmansour Hulumi 服务供应链问题漏洞
Vulnerability Description
Kerberosmansour Hulumi是Kerberosmansour个人开发者的一个面向Pulumi的云基础设施安全工具包。 Kerberosmansour Hulumi 1.4.0之前版本存在服务供应链问题漏洞,该漏洞源于AccountFoundation组件设计问题,可能导致具备S3删除权限的主体删除CloudTrail和Config审计日志。
CVSS Information
N/A
Vulnerability Type
N/A