在 AWS IAM Identity Center 解决方案中的临时提升权限管理(TEAM)版本 1.5.1 之前的版本中,存在错误的权限分配问题。该缺陷可能允许拥有应用级别访问权限的已认证远程用户读取、批准、修改或撤销任意的访问请求,从而通过 TEAM 部署所连接的 AWS 账户获得非预期的临时提升权限。 该问题已在 TEAM 1.5.1 及更高版本中修复。建议升级到最新版本,并确保任何分支或衍生代码也已应用相应的补丁以纳入新修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | iam-identity-center-team | < 1.5.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | iam-identity-center-team | 0 ~ 1.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet