CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild
wiz.io | blog | #cloud | #supply-chain | #aws | #github | #ci-cd | #vulnerability | #wiz-research | #codebuild
Summary
CodeBreach: two missing regex characters in AWS CodeBuild pipelines let unauthenticated attackers leak credentials and take over key AWS GitHub repos, including the Console's JavaScript SDK.
- Published
- Collected
Skip to content