Nov. 21, 2022, midnight |

The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org

Prior to September 6, 2022, the AWS AppSync service could be coerced
to assume arbitrary roles which trusted the AppSync service. This was
due to insufficient validation of a serviceRoleArn parameter, allowing
an attacker to specify roles in other accounts. With this vulnerability,
an adversary could invoke arbitrary AWS API calls with the compromised role.

appsync aws

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC