以下是该漏洞描述的中文翻译: @hulumi/policies 在 1.3.2 版本之前的版本中存在一个父级身份伪造绕过漏洞。该漏洞允许攻击者在策略评估过程中提交伪造的 SecureBucket 父级证据。攻击者可以通过提供伪造的证据来绕过安全策略检查,导致验证器未能发现不安全的存储桶(bucket)配置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82860 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 Admin Policy Bypass |
| CVE-2026-82858 | 9.8 CRITICAL | @hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance |
| CVE-2026-82856 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 OIDC Trust Policy Bypass |
| CVE-2026-82855 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 Evidence Validation Bypass |
| CVE-2026-82863 | 3.3 LOW | @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection |
No comments yet