VDB

GCVE-110-CLOUD-2020-0026

GCVE-110-CLOUD-2020-0026
Advisory Published
Vulnetix · Advisory published April 23, 2020
GuardDuty detected CloudTrail being outright disabled, but did not detect if an attacker with the necessary permissions filtered out all events from CloudTrail via PutEventSelectors, resulting in defenders having no logs to review. AWS fixed this issue by adding a GuardDuty detection that triggers if PutEventSelectors is used to disable all event types.

Affected Products

VendorProductVersionsPlatforms
AWSCloudTrail
AWSGuardDuty

References

advisory
advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›