VDB
GCVE-110-CLOUD-2020-0026
GCVE-110-CLOUD-2020-0026
Advisory Published
GuardDuty detected CloudTrail being outright disabled, but did not detect if an attacker with the
necessary permissions filtered out all events from CloudTrail via PutEventSelectors, resulting in
defenders having no logs to review. AWS fixed this issue by adding a GuardDuty detection that
triggers if PutEventSelectors is used to disable all event types.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| AWS | CloudTrail | — | — |
| AWS | GuardDuty | — | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.