Junglewise Threat Intelligence

CVE-2025-14503: AWS Harmonix privilege escalation in EKS provisioning role

CVE-2025-14503 · Severity: high · Published 2025-12-15

Technologies: Amazon AWS. Vendors: AWS, Amazon Web Services, Amazon.

Executive brief

Harmonix on AWS, an open-source platform for developers, contains a security flaw in its default configuration for Amazon EKS environments. This flaw could allow a standard user within the AWS account to gain administrative control over the platform. Organizations using this framework should update to the latest version to prevent unauthorized privilege escalation.

Technical details

A vulnerability exists in the Harmonix on AWS framework (v0.3.0 through v0.4.1) due to an overly permissive IAM trust policy in the sample code for the EKS environment provisioning role. The role is configured to trust the account root principal, which allows any IAM principal in the account with 'sts:AssumeRole' permissions to assume the provisioning role. Because this role typically possesses administrative privileges, an attacker can achieve full control over the EKS environment. The issue is resolved in version 0.4.2 by narrowing the trust relationship.

Affected products

  • AWS Harmonix on AWS v0.3.0 - v0.4.1

Timeline

  • 2025-12-15: disclosed
  • 2025-12-15: patched: Fixed in version 0.4.2
  • 2025-12-15: advisory

References

Related threats