CVE-2024-28056: Critical severity Amazon AWS Amplify CLI vulnerability

Published Apr 15, 2024
·
Updated

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" remains present, and consequently sts:AssumeRoleWithWebIdentity would be available to threat actors with no conditions. Thus, if Amplify CLI had been used to remove the Authentication component from a project built between August 2019 and January 2024, an "assume role" may have occurred, and may have been leveraged to obtain unauthorized access to an organization's AWS resources. NOTE: the problem could only occur if an authorized AWS user removed an Authentication component. (The vulnerability did not give a threat actor the ability to remove an Authentication component.) However, in realistic situations, an authorized AWS user may have removed an Authentication component, e.g., if the objective were to stop using built-in Cognito resources, or move to a completely different identity provider.

Affected Software

2 affected componentsFixes available
npm/@aws-amplify/cli<12.10.1
12.10.1
Amazon AWS Amplify CLI<12.10.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@aws-amplify/cli to a version that resolves this vulnerability.

    Fixed in 12.10.1
  2. Upgrade

    Upgrade Amazon AWS Amplify CLI to a version that resolves this vulnerability.

    Fixed in 12.10.1
  3. Configuration

    After using Amplify CLI to remove the Authentication component from an Amplify project built between August 2019 and January 2024, review the IAM roles associated with the Amplify project and ensure the trust policy does not retain Effect:"Allow" without the required Condition—specifically ensure the Condition property required to restrict sts:AssumeRoleWithWebIdentity is present so AssumeRoleWithWebIdentity is not available without conditions.

    IAM role trust policy for Amplify projects (sts:AssumeRoleWithWebIdentity) Condition property in trust policy (Condition with conditions for AssumeRoleWithWebIdentity) = Restored/ensured
  4. Compensating control

    For affected Amplify projects (those where Authentication was removed via Amplify CLI for projects built between August 2019 and January 2024), restrict/limit the IAM role assumption paths at the AWS account level (e.g., via IAM/role trust policy constraints) so that sts:AssumeRoleWithWebIdentity cannot be used by unauthorized principals in the absence of the removed Condition.

Event History

Apr 15, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyAffected Software
Advisory Published
via GitHub·06:30 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-28056?

CVE-2024-28056 has been classified as a medium severity vulnerability due to improper IAM role trust policy configurations.

2

How do I fix CVE-2024-28056?

To fix CVE-2024-28056, upgrade the AWS Amplify CLI to version 12.10.1 or later.

3

What software is affected by CVE-2024-28056?

CVE-2024-28056 affects versions of the AWS Amplify CLI prior to 12.10.1.

4

What impact does CVE-2024-28056 have?

CVE-2024-28056 can lead to unintended IAM role permissions, which may compromise cloud security.

5

Is there a workaround for CVE-2024-28056?

Currently, the best course of action is to upgrade to AWS Amplify CLI version 12.10.1 or later as there is no known workaround.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203