Wiz Research discovered CodeBreach, a critical supply chain vulnerability in AWS CodeBuild that enabled complete takeover of key AWS GitHub repositories, including the JavaScript SDK powering the AWS Console. The flaw stemmed from unanchored regex patterns in ACTOR_ID webhook filters, allowing attackers to bypass authentication
Table of contents
Required Actions and MitigationsWhy We Audited CodeBuildUnanchored: How a Subtle Flaw Led to CI CompromiseFrom Bypass to Admin: Executing the TakeoverConclusionStatement from AWSResponsible Disclosure TimelineStay in touch!Sort: