VDB

GCVE-110-CLOUD-2019-0009

GCVE-110-CLOUD-2019-0009
Advisory Published
Vulnetix · Advisory published June 18, 2019
The AWS CodeStar service had an undocumented API (codestar:CreateProjectFromTemplate) that allowed users with broadly-scoped CodeStar permissions to create a CodeStar project. As part of the creation process, AWS would create a new CodeStarWorker IAM policy & attach it to the user making the call. This policy granted full access to over 50 AWS services, including iam:AttachRolePolicy, iam:AttachUserPolicy and iam:PutRolePolicy permissions, which would allow the user to escalate to full administrator access. Following disclosure, AWS removed the majority of access granted by the CodeStarWorker policy, but this is still a viable escalation path if there are other misconfigurations in the environment.

Affected Products

VendorProductVersionsPlatforms
AWSIAM
AWSConfig
AWSCodestar

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›