在 1.3.2 之前的版本未能正确验证 GitHub OIDC 信任策略中带作用域的 AWS IAM 条件运算符。攻击者可以利用 运算符,将通配符形式的 GitHub Actions OIDC subject 条件隐藏在安全护栏(security guardrails)之外,从而绕过安全检查。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82860 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 Admin Policy Bypass |
| CVE-2026-82858 | 9.8 CRITICAL | @hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance |
| CVE-2026-82855 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 Evidence Validation Bypass |
| CVE-2026-82861 | 7.5 HIGH | @hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass |
| CVE-2026-82863 | 3.3 LOW | @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection |
No comments yet