Incorrect Default Permissions Affecting basti-cdk package, versions <1.0.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Default Permissions vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-BASTICDK-5862949
  • published29 Aug 2023
  • disclosed24 Aug 2023
  • creditRami McCarthy

Introduced: 24 Aug 2023

CVE NOT AVAILABLE CWE-276  (opens in a new tab)

How to fix?

Upgrade basti-cdk to version 1.0.1 or higher.

Overview

basti-cdk is a construct library that allows you to create cost-efficient bastion instances and easily connect to your infrastructure with Basti CLI.

Affected versions of this package are vulnerable to Incorrect Default Permissions via the bastic connect function due to missing ssm:SessionDocumentAccessCheck in the provided Minimal IAM Policy. An attacker can get a shell session on the bastion, not just the intended access for Port Forwarding.

References

CVSS Scores

version 3.1