Skip to content

Kamus decryptor does not verify service account with AWS KMS

High
shaikatz published GHSA-rj3q-mm8q-45gg Jun 7, 2020

Package

No package listed

Affected versions

< 0.7.0.0

Patched versions

0.7.0.0

Description

Impact

Due to a bug in the AWS decryption code, any service account could decrypt secrets - not only the service account that creates it.

Patches

Users should upgrade to version 0.7.0.0

Workarounds

None

References

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs

Credits