VDB

GCVE-110-CLOUD-2024-0046

GCVE-110-CLOUD-2024-0046
Advisory Published
Vulnetix · Advisory published March 27, 2024
A flaw in AWS Bedrock's foundation model access control allowed unauthorized subscriptions to certain models, bypassing IAM policies using the aws-marketplace:ProductId condition key. This could lead to compliance issues and financial risks. AWS has since fixed the issue and notified affected customers.

Affected Products

VendorProductVersionsPlatforms
AWSIAM
AWSAmazon Bedrock, AWS Marketplace
AWSBedrock

Browse GCVE Records

74,496 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›