In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Incorrect Default Permissions vulnerabilities in an interactive lesson.
Start learningUpgrade basti-cdk
to version 1.0.1 or higher.
basti-cdk is a construct library that allows you to create cost-efficient bastion instances and easily connect to your infrastructure with Basti CLI.
Affected versions of this package are vulnerable to Incorrect Default Permissions via the bastic connect
function due to missing ssm:SessionDocumentAccessCheck
in the provided Minimal IAM Policy. An attacker can get a shell session on the bastion, not just the intended access for Port Forwarding.