VDB

GCVE-110-CLOUD-2023-0052

GCVE-110-CLOUD-2023-0052
Advisory Published
Vulnetix · Advisory published February 25, 2023
For AWS CodeBuild, when using a custom container image stored in ECR and the project service role for the credentials to pull the image, the default IAM policy attached to the role to allow pulling the container was over-privileged and allowed the CodeBuild container to overwrite its own build image. An attacker with the ability to read the container credentials from the meta-data service or run commands within the container could thereby overwrite the container to gain persistence within the CodeBuild project.

Affected Products

VendorProductVersionsPlatforms
AWSIAM
AWSAWS CodeBuild, AWS ECR
AWSCodeBuild
AWSECR

Browse GCVE Records

74,557 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›