Collected research
The Danger of Falling to System Role in AWS SDK Client
The AWS SDK credential provider chain silently falls back to the host machine's own IAM role when a client is initialised with nil credentials. A web application whose import-from-S3 feature set credentials to nil in its error handler therefore retried the request as the privileged system role, letting any user read the platform's internal private buckets by naming them.
Record
- Researcher
- Francesco Lacerenza and Mohamed Ouad
- Published by
- blog.doyensec.com
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Francesco Lacerenza and Mohamed Ouad, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .