PT-2018-13255 · Amazon+1 · Aws Cli+3

Swampdragon

·

Published

2018-08-25

·

Updated

2024-06-15

·

CVE-2018-15869

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Amazon Web Services (AWS) (affected versions not specified)
Description The issue arises when an AWS developer fails to specify the --owners flag while describing images via AWS CLI, which leads to not properly validating the source software according to AWS recommended security best practices. This oversight may cause the unintentional loading of an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurated public community AMI catalog.
Recommendations For AWS CLI users, as a temporary workaround, consider specifying the --owners flag when describing images to ensure proper validation of source software. Restrict access to the public community AMI catalog to minimize the risk of exploitation. Avoid loading AMIs from untrusted sources until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15869
OPENSUSE-SU-2024:10644-1
SUSE-RU-2018:4074-1
SUSE-SU-2020:0251-1
SUSE-SU-2020_0251-1

Affected Products

Aws
Aws Cli
Amazon Machine Image
Suse