Back

HIGH

AccessKeyID validation bypass

Published Jul 12, 2022

Description

A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.

Affected products

Remediation

Vendor solution

Prior to upgrading, this vulnerability can be mitigated by not using the {{AccessKeyID}} template value to construct usernames.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Jul 12, 2022
Updated Sep 16, 2024
Reserved Jul 11, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 11, 2022
GHSA-PP3F-98QG-5G75