THREATOPS
THREAT OPSThreat News › [NVD] CVE-2024-28056 (CRITICAL 9.8) — Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" remains present, and conseq

[NVD] CVE-2024-28056 (CRITICAL 9.8) — Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" remains present, and conseq

lownvdPublished 2024-04-15

CVE-2024-28056 CVSS: 9.8 CRITICAL Published: 2024-04-15T18:15:10.723

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" remains present, and consequently sts:AssumeRoleWithWebIdentity would be avai

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-28056