VDB
GCVE-110-CLOUD-2023-0052
GCVE-110-CLOUD-2023-0052
Advisory Published
For AWS CodeBuild, when using a custom container image stored in ECR and the
project service role for the credentials to pull the image, the default IAM
policy attached to the role to allow pulling the container was over-privileged
and allowed the CodeBuild container to overwrite its own build image.
An attacker with the ability to read the container credentials from the meta-data
service or run commands within the container could thereby overwrite the container to gain
persistence within the CodeBuild project.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| AWS | IAM | — | — |
| AWS | AWS CodeBuild, AWS ECR | — | — |
| AWS | CodeBuild | — | — |
| AWS | ECR | — | — |
Browse GCVE Records
74,557 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.