OSV 1.4.0 · unreviewed · 修改于 2026-08-31 17:30
发布时间
2026-08-31 17:30
GitHub 审查时间
—
NVD 发布时间
2026-08-31 17:17
源文件
advisories/unreviewed/2026/08/GHSA-pjj3-j4q3-9wpg/GHSA-pjj3-j4q3-9wpg.json
hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account.
该公告没有提供结构化的受影响软件包信息。