@hulumi/baseline 1.3.2 之前的版本无法完全检测 CloudTrail 选择器篡改事件,从而降低了审计日志配置变更的覆盖范围。攻击者可以在未被完全检测的情况下修改 CloudTrail 事件选择器,从而可能规避审计跟踪监控。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82860 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 Admin Policy Bypass |
| CVE-2026-82858 | 9.8 CRITICAL | @hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance |
| CVE-2026-82856 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 OIDC Trust Policy Bypass |
| CVE-2026-82855 | 9.8 CRITICAL | @hulumi/policies before 1.3.2 Evidence Validation Bypass |
| CVE-2026-82861 | 7.5 HIGH | @hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass |
No comments yet