First published: Sat Aug 25 2018(Updated: )
An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurated public community AMI catalog.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hashicorp Packer | <1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15869 is considered a moderate severity vulnerability due to the potential risk of deploying malicious Amazon Machine Images.
To mitigate CVE-2018-15869, ensure that you always specify the --owners flag when using the AWS CLI to describe images.
CVE-2018-15869 can potentially lead to the deployment of unauthorized and harmful AMIs, affecting the security of your AWS environment.
Developers and users of HashiCorp Packer prior to version 1.3.0 who utilize the AWS CLI without proper flags are at risk from CVE-2018-15869.
Using HashiCorp Packer with AWS without mitigation for CVE-2018-15869 can expose your environment to risks from malicious AMIs.