PT-2026-48476 · Npm+2 · @Hulumi/Policies+1
CVE-2026-48034
·
Published
2026-06-10
·
Updated
2026-07-24
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
@hulumi/policies versions prior to 1.4.0
Description
A bypass exists in the H5 defense-in-depth check of the Hulumi hardening pack. The H5 check is designed to verify that raw
aws:s3:Bucket resources acting as children of a SecureBucket component possess five mandatory hardening sibling resources: public-access block, SSE-KMS, ownership controls, versioning, and a TLS-only bucket policy. The issue occurs because the check only verified the types of these sibling resources without confirming they were actually applied to the specific bucket being exempted. An attacker or a compromised pull request could associate an unhardened raw bucket with five decoy sibling resources that point to a different bucket, causing the policy pack to incorrectly report the stack as compliant while the actual bucket remains unhardened.Recommendations
Upgrade to @hulumi/policies version 1.4.0.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Hulumi/Policies
Hulumi