Executive brief
@hulumi/baseline is a security tool used to monitor and enforce audit logging configurations in AWS environments. A vulnerability was identified where the tool failed to detect certain unauthorized changes to AWS CloudTrail event selectors. This could allow an attacker to modify logging settings to hide their activities without being flagged by the monitoring system.
Technical details
A vulnerability classified as Insufficient Logging (CWE-778) exists in @hulumi/baseline versions prior to 1.3.2. The software's detection logic for AWS CloudTrail event-selector tampering was incomplete, meaning certain modifications to audit logging configurations would not trigger alerts. This flaw reduces the effectiveness of security monitoring by allowing an attacker with sufficient AWS permissions to suppress logging for specific activities without detection by the baseline tool. The issue is addressed in version 1.3.2 by expanding detection coverage and adding regression tests.
Affected products
- kerberosmansour @hulumi/baseline < 1.3.2
Timeline
- 2026-05-15: disclosed
- 2026-05-21: advisory
- 2026-05-15: patched: Version 1.3.2 released