VDB

GCVE-110-CLOUD-2023-0051

GCVE-110-CLOUD-2023-0051
Advisory Published
Vulnetix · Advisory published February 25, 2023
An attacker with elevated permissions in CodeBuild could leak the configured credentials for Github/Bitbucket. This was possible by configuring the http_proxy and https_proxy variables, which would allow you to capture the credentials via MITM.

Affected Products

VendorProductVersionsPlatforms
AWSAWS CodeBuild
AWSCloud Services
AWSConfig
AWSCodeBuild

References

advisory
advisory

Browse GCVE Records

74,132 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›