medium

3rd party vendor confused deputy via AssumeRole

Published Wed, Nov 16th, 2016

Platforms

aws

Summary

3rd party vendors can (and sometimes do) incorrectly implement sts:ExternalId in their AWS role trust policies, leading to confused deputy issues. These misconfigurations could allow customers to access other customers' data. Although vendors are responsible for ensuring their own configurations are correct, AWS could theoretically add mitigations to prevent and detect this issue.

Affected Services

N/A

Remediation

Audit your vendor roles.

Tracked CVEs

No tracked CVEs

References

Contributed by https://github.com/0xdabbad00

Entry Status

Finalized

Disclosure Date

Wed, Nov 16th, 2016

Exploitability Period

ongoing

Known ITW Exploitation

-

Detection Methods

None

Piercing Index Rating

-

Discovered by

Daniel Grzelak, Atlassian