Kerberosmansour Hulumi是Kerberosmansour个人开发者的一个面向Pulumi的云基础设施安全工具包。 Kerberosmansour Hulumi 1.4.0之前版本存在处理逻辑错误漏洞,该漏洞源于AccountFoundation重用路径问题,可能导致GuardDuty/Security Hub状态被静默降级。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kerberosmansour | hulumi | < 1.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kerberosmansour | hulumi | < 1.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48034 | 8.5 HIGH | HULUMI-H5 bypass via decoy sibling resources targeting a different bucket |
| CVE-2026-48036 | 8.4 HIGH | Hulumi: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts |
| CVE-2026-48033 | 8.4 HIGH | Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name |
| CVE-2026-48032 | 8.3 HIGH | Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers |
| CVE-2026-48035 | 7.1 HIGH | Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened |
No comments yet