VDB

GCVE-110-CLOUD-2024-0013

GCVE-110-CLOUD-2024-0013
Advisory Published
Vulnetix · Advisory published October 15, 2024
CloudTrail delivered events to the resource owner and API caller even when the API action was denied by the VPC endpoint policy. This could have enabled a stealthy data exfiltration method in cases where an attacker had previously compromised a VPC, by smuggling data through the user agent field in denied requests.

Affected Products

VendorProductVersionsPlatforms
AWSVPC Endpoints
AWSCloudTrail
AWSSES

Browse GCVE Records

74,198 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›