VDB
GCVE-110-CLOUD-2024-0013
GCVE-110-CLOUD-2024-0013
Advisory Published
CloudTrail delivered events to the resource owner and API caller even when the API action was denied by the VPC endpoint policy.
This could have enabled a stealthy data exfiltration method in cases where an attacker had previously compromised a VPC, by smuggling data through the user agent field in denied requests.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| AWS | VPC Endpoints | — | — |
| AWS | CloudTrail | — | — |
| AWS | SES | — | — |
Browse GCVE Records
74,198 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.