在 1.3.2 版本之前,对外部提供的执行计划(execute plans)缺乏充分的来源验证,导致不受信任的对账(reconciliation)输入可能被当作受信任输入处理。攻击者可以提交恶意的执行计划以绕过安全检查,从而执行不安全的对账操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82860 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 Admin Policy Bypass |
| CVE-2026-82856 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 OIDC Trust Policy Bypass |
| CVE-2026-82855 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 Evidence Validation Bypass |
| CVE-2026-82861 | 7.5 HIGH | @hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass |
| CVE-2026-82863 | 3.3 LOW | @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection |
No comments yet