PT-2025-51281 · Unknown+1 · Harmonix On Aws+1
CVE-2025-14503
·
Publicado
2025-12-15
·
Atualizado
2025-12-21
CVSS v4.0
8.6
Alta
| Vetor | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Harmonix on AWS versions 0.3.0 through 0.4.1
Description
An overly-permissive IAM trust policy within the Harmonix on AWS framework could allow IAM principals within the same AWS account to escalate privileges through role assumption. The EKS environment provisioning role’s sample code is configured to trust the account root principal, potentially enabling any IAM principal in the same AWS account possessing
sts:AssumeRole permissions to assume the role and gain administrative privileges.Recommendations
Upgrade to Harmonix on AWS version 0.4.2 or later.
Exploit
Correção
Incorrect Privilege Assignment
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Eks
Harmonix On Aws