2.0.3
3 months ago
7 days ago
Known vulnerabilities in the @hulumi/policies package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@hulumi/policies is a Pulumi CrossGuard policy packs for AWS, GitHub, Kubernetes, Cloudflare, and deployment governance. Includes HulumiHardeningPack, HulumiAwsOrgHardeningPack, state/backend/primitive/detection rules, GitHub packs, EKS packs, and platform governance. SLSA Bui Affected versions of this package are vulnerable to Access Control Bypass through the exemption mechanism for raw S3 buckets in the hardening policy check. An attacker can deploy an unhardened S3 bucket without required security controls by pairing it with decoy sibling resources that reference a different bucket, causing the compliance check to pass incorrectly. How to fix Access Control Bypass? Upgrade | <1.4.0 |
@hulumi/policies is a Pulumi CrossGuard policy packs for AWS, GitHub, Kubernetes, Cloudflare, and deployment governance. Includes HulumiHardeningPack, HulumiAwsOrgHardeningPack, state/backend/primitive/detection rules, GitHub packs, EKS packs, and platform governance. SLSA Bui Affected versions of this package are vulnerable to Incorrect Comparison in the policy validation process. An attacker can bypass intended policy enforcement by configuring an IAM role to trust multiple OIDC providers, causing the validation to incorrectly skip checks for overly permissive wildcard conditions. How to fix Incorrect Comparison? Upgrade | <1.4.0 |
@hulumi/policies is a Pulumi CrossGuard policy packs for AWS, GitHub, Kubernetes, Cloudflare, and deployment governance. Includes HulumiHardeningPack, HulumiAwsOrgHardeningPack, state/backend/primitive/detection rules, GitHub packs, EKS packs, and platform governance. SLSA Bui Affected versions of this package are vulnerable to Protection Mechanism Failure through the URN parsing process. An attacker can bypass mandatory hardening checks by crafting a logical name containing trusted substrings, causing policy exemptions to be incorrectly applied. How to fix Protection Mechanism Failure? Upgrade | <1.4.0 |