VDB

GCVE-110-CLOUD-2022-0005

GCVE-110-CLOUD-2022-0005
Advisory Published
Vulnetix · Advisory published November 21, 2022
The AWS AppSync service could be coerced to assume arbitrary roles in other customers' accounts which trusted the AppSync service. This was due to insufficient validation of a serviceRoleArn parameter (caused by a case-sensitivity parsing issue). With this vulnerability, if an adversary knew the ARN of the role associated with AppSync in the target account, they could use it invoke arbitrary AWS API calls.

Affected Products

VendorProductVersionsPlatforms
AWSCloud Services
AWSAppSync

References

advisory
advisory

Browse GCVE Records

74,496 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›