@hulumi/policies 1.3.2 之前的版本未能对“管理员策略”护栏(administrator-policy guardrail)的内联及关联式 IAM 策略证据进行完整检查。攻击者可以构造出与管理员权限等效的策略路径,从而绕过策略评估控制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82858 | 9.8 CRITICAL | @hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance |
| CVE-2026-82856 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 OIDC Trust Policy Bypass |
| CVE-2026-82855 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 Evidence Validation Bypass |
| CVE-2026-82861 | 7.5 HIGH | @hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass |
| CVE-2026-82863 | 3.3 LOW | @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection |
No comments yet