THREAT OPS › Threat News › [NVD] CVE-2024-28056 (CRITICAL 9.8) — Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" remains present, and conseq
[NVD] CVE-2024-28056 (CRITICAL 9.8) — Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" remains present, and conseq
CVE-2024-28056 CVSS: 9.8 CRITICAL Published: 2024-04-15T18:15:10.723
Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" remains present, and consequently sts:AssumeRoleWithWebIdentity would be avai
Indicators of compromise
- CVE-2024-28056cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-28056