PT-2022-16291 · Amazon+1 · Aws-Iam-Authenticator+1

Gafnit Amiga

·

Published

2022-07-12

·

Updated

2024-08-21

·

CVE-2022-2385

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions aws-iam-authenticator versions prior to 0.5.9
Description A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.
Recommendations For versions prior to 0.5.9, update to version 0.5.9 or later to resolve the issue. As a temporary workaround, consider restricting access to allow-listed IAM identities to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-2385
GHSA-PP3F-98QG-5G75
GO-2022-0547
OPENSUSE-SU-2022_2583-1
SUSE-SU-2022:2583-1
SUSE-SU-2022_2583-1

Affected Products

Suse
Aws-Iam-Authenticator