VDB

GCVE-110-CLOUD-2024-0047

GCVE-110-CLOUD-2024-0047
Advisory Published
Vulnetix · Advisory published March 24, 2024
TrustOnCloud identified a flaw in how AWS Bedrock enforces IAM access controls using the aws-marketplace:ProductId condition key, which is meant to restrict subscriptions to specific foundation models. Their testing revealed that some Bedrock models, including those from Cohere and Stability AI, were not consistently blocked or allowed as intended by IAM policies, posing potential compliance and cost risks. AWS acknowledged and fixed the issue, notifying affected customers and updating testing procedures to prevent future issues.

Affected Products

VendorProductVersionsPlatforms
AWSIAM
AWSAWS Bedrock
AWSBedrock

Browse GCVE Records

74,198 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›