Junglewise Threat Intelligence

basti-cdk insufficient IAM policy validation

Severity: info · Published 2023-08-24

Vendors: npm.

Executive brief

basti-cdk is an AWS infrastructure tool that deploys secure bastion instances for database access via port forwarding. The minimal IAM policy provided in documentation omits a critical condition check (ssm:SessionDocumentAccessCheck), allowing users to gain interactive shell access to the bastion instead of only port forwarding capability. This could expose downstream credentials stored on the bastion to unauthorized users.

Technical details

The vulnerability stems from an incomplete IAM policy in the basti-cdk documentation that fails to enforce the ssm:SessionDocumentAccessCheck condition. The minimal policy allows ssm:StartSession action on the bastion instance and the AWS-StartPortForwardingSessionToRemoteHost document, but without the SessionDocumentAccessCheck condition, AWS IAM logic implicitly grants access to other session manager documents including SSM-SessionManagerRunShell. This is a configuration/policy design flaw requiring explicit policy updates. An authenticated AWS IAM principal with the minimal policy can invoke an interactive shell session on the bastion EC2 instance rather than only port forwarding. The vulnerability was patched in version 1.0.1 by adding the missing condition to the recommended IAM policy.

Affected products

  • Bohdan Petryshyn basti-cdk before 1.0.1

Timeline

  • 2023-08-24: disclosed
  • 2023-08-24: patched: Fixed in version 1.0.1

References