Published Mon, Jul 27th, 2020
Platforms
Using CloudTrail S3 data events, it was possible to determine the AWS account ID of any existing S3 bucket by calling any S3 API, getting denied, and looking at the value in the resource key in error message that showed up in CloudTrail.
S3
None required
No tracked CVEs
Contributed by https://github.com/jon-trust
Entry Status
Finalized
Disclosure Date
Mon, Jul 27th, 2020
Exploitability Period
until 2022/07/08
Known ITW Exploitation
-
Detection Methods
None
Piercing Index Rating
-
Discovered by
Jonathan Rault, TrustOnCloud