Listen to this Post
How the mentioned CVE works:
The vulnerability resides in the OpenBao `auth-aws` plugin’s caching mechanism for IAM role authentication. When an IAM role attempts to authenticate, the plugin generates a cache key based on the role’s name and other parameters, but critically omits the AWS Account ID. If an attacker controls an IAM role in an untrusted AWS account that has the same name as a trusted role in a different, trusted account, they can exploit this flaw. The plugin’s cache will return a valid authentication for the trusted role when the attacker’s role authenticates, because the cache key is identical. This allows the attacker from the untrusted account to impersonate the trusted role, bypassing authorization checks. The attack can succeed even with explicitly configured role ARNs (without wildcards) if a role name collision exists, as the account ID is not validated against the bound principal ARN.
DailyCVE Form:
Platform: OpenBao
Version: <0.1.1
Vulnerability: Cross-Account Impersonation
Severity: High
date: 2024-XX-XX
Prediction: Patch 2024-XX-XX
What Undercode Say:
Simulating the flawed cache key generation (vulnerable version)
TRUSTED_ARN="arn:aws:iam::123456789:role/MyAppRole"
MALICIOUS_ARN="arn:aws:iam::ATTACKER_ACCOUNT:role/MyAppRole"
The plugin generates the same cache key for both ARNs
echo "Generating cache key:"
echo "$TRUSTED_ARN" | awk -F':' '{print $NF}' Output: role/MyAppRole
echo "$MALICIOUS_ARN" | awk -F':' '{print $NF}' Output: role/MyAppRole
Command to check installed plugin version
openbao read sys/plugins/catalog/auth/aws
How Exploit:
- Identify a target OpenBao instance using the `auth-aws` plugin.
- Enumerate trusted IAM role names via reconnaissance or information leakage.
- In a controlled, untrusted AWS account, create an IAM role with a name identical to a trusted role.
- Use the malicious IAM role to authenticate against the vulnerable OpenBao endpoint.
- The flawed cache returns a valid token for the trusted role, granting unauthorized access.
Protection from this CVE:
Immediate upgrade to `auth-aws` plugin version 0.1.1.
Enforce unique IAM role names across all AWS accounts.
Implement a naming convention with account IDs.
Audit and rename duplicate roles.
Remove wildcards from `bound_iam_principal_arn`.
Impact:
Unauthorized secret access.
Data exfiltration.
Privilege escalation.
Full Vault compromise.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

