GHSA-846g-p7hm-f54r
CRITICALCVE-2024-28056Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" remains present, and consequently sts:AssumeRoleWithWebIdentity would be available to threat actors with no conditions. Thus, if Amplify CLI had be
- Affected
- < 12.10.1
- Fixed in
- 12.10.1
- Weakness
- CWE-269
- Published
- 2024-04-15
- Source
- github