low

AWS AppStream Cloudtrail Bypass

Published Mon, Sep 11th, 2023

Platforms

aws

Summary

Credentials can be extracted from AppStream. When used, they obscure the sourceIP and userName of the initial user. The sourceIP appears as appstream.amazonaws.com.

Affected Services

AppStream

Remediation

None required

Tracked CVEs

No tracked CVEs

References

Contributed by https://github.com/ramimac

Entry Status

Finalized

Disclosure Date

Mon, Sep 11th, 2023

Exploitability Period

ongoing

Known ITW Exploitation

-

Detection Methods

None

Piercing Index Rating

-

Discovered by

Saransh Rana, CRED