@hulumi/policies 在 1.3.2 之前的版本中,Cloudflare 和 deployment-governance 验证器中存在一个证据验证绕过漏洞。该漏洞允许攻击者通过提交不相关的合规证据来抑制违规项。攻击者可以利用来自不同区域、主机名、源站或仓库的证据,绕过同一堆栈中与这些资源无关的安全防护措施。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82860 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 Admin Policy Bypass |
| CVE-2026-82858 | 9.8 CRITICAL | @hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance |
| CVE-2026-82856 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 OIDC Trust Policy Bypass |
| CVE-2026-82861 | 7.5 HIGH | @hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass |
| CVE-2026-82863 | 3.3 LOW | @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection |
No comments yet