Executive brief
Hulumi is a toolkit used to deploy secure cloud infrastructure using Pulumi. A security flaw allowed developers or malicious actors to bypass mandatory security checks (such as encryption or access controls) by carefully naming their cloud resources. This could result in the deployment of insecure infrastructure, such as unencrypted storage buckets or misconfigured network settings, while falsely appearing to comply with corporate security policies.
Technical details
A protection mechanism failure (CWE-693) exists in @hulumi/policies prior to version 1.4.0. The toolkit identifies trusted parent components by performing substring matching on Pulumi Uniform Resource Names (URNs). Because Pulumi URNs include a developer-controlled logical name suffix, an attacker can inject trusted type strings (e.g., 'SecureBucket