low

AWS CodeBuild Token Leakage

Published Sat, Feb 25th, 2023
Platforms

Summary

An attacker with elevated permissions in CodeBuild could leak the configured credentials for Github/Bitbucket. This was possible by configuring the http_proxy and https_proxy variables, which would allow you to capture the credentials via MITM.

Affected Services

AWS CodeBuild

Remediation

None required

Tracked CVEs

No tracked CVEs

References

Disclosure Date
Wed, Jan 18th, 2023
Exploitablity Period
-
Known ITW Exploitation
-
Detection Methods
-
Piercing Index Rating
-
Discovered by
Carlos Polop, Halborn