VDB
GCVE-110-CLOUD-2024-0047
GCVE-110-CLOUD-2024-0047
Advisory Published
TrustOnCloud identified a flaw in how AWS Bedrock enforces IAM access controls using the
aws-marketplace:ProductId condition key, which is meant to restrict subscriptions to specific
foundation models. Their testing revealed that some Bedrock models, including those from Cohere
and Stability AI, were not consistently blocked or allowed as intended by IAM policies, posing
potential compliance and cost risks. AWS acknowledged and fixed the issue, notifying affected
customers and updating testing procedures to prevent future issues.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| AWS | IAM | — | — |
| AWS | AWS Bedrock | — | — |
| AWS | Bedrock | — | — |
Browse GCVE Records
74,198 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.