VDB

GCVE-110-CLOUD-2024-0012

GCVE-110-CLOUD-2024-0012
Advisory Published
Vulnetix · Advisory published October 15, 2024
A vulnerability in AWS CloudShell allowed users to gain unintended command-line access to the underlying AWS infrastructure. During a training session, a delegate unexpectedly received the identity context of an EC2 instance role within an ECS cluster, instead of the intended AWS account. This issue potentially bypassed existing controls aimed at preventing lateral movement and access to higher-privileged management roles.

Affected Products

VendorProductVersionsPlatforms
AWSECS
AWSCloud Services
AWSCloudShell
AWSEC2
AWSSES

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›