bengriffiths avatar

@bengriffiths

in /infosec 11 days ago

Wiz Research take over key AWS repos

CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild - Featured Image

CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild

www.wiz.io - faviconwiz.io
TLDR

Wiz Research discovered a critical supply chain vulnerability in AWS CodeBuild that could have allowed attackers to take over key AWS GitHub repositories, including the JavaScript SDK powering the AWS Console. The vulnerability stemmed from a misconfiguration in how the repositories’ AWS CodeBuild CI pipelines handled build triggers, allowing unauthenticated attackers to infiltrate the build environment and leak privileged credentials. Wiz responsibly disclosed the findings to AWS, which promptly remediated the issue and implemented global hardening measures within the CodeBuild service to prevent similar attacks.

2Score: 2

0 Comments