In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Incorrect Default Permissions vulnerabilities in an interactive lesson.
Start learningUpgrade basti-cdk to version 1.0.1 or higher.
basti-cdk is a construct library that allows you to create cost-efficient bastion instances and easily connect to your infrastructure with Basti CLI.
Affected versions of this package are vulnerable to Incorrect Default Permissions via the bastic connect function due to missing ssm:SessionDocumentAccessCheck in the provided Minimal IAM Policy. An attacker can get a shell session on the bastion, not just the intended access for Port Forwarding.