wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
306 stars 61 forks source link

Added Cloudtrail bypass for both read and write actions in AWS Service Catalog #143

Closed Frichetten closed 1 year ago

Frichetten commented 1 year ago

We just publicly disclosed this vulnerability in AWS Service Catalog. By abusing a dev endpoint you could bypass CloudTrail logging for both read AND write actions in Service Catalog.

Disclosure Timeline

January 30, 2023: Datadog reports both issues to AWS. January 30, 2023: AWS responds that they received the report. February 7, 2023: AWS confirms that a fix is in development. February 7, 2023: AWS deploys fix to Service Catalog. March 20, 2023: Datadog releases public disclosure.