GHSA-5pxh-34gw-xxq6HighCVSS 3.3

@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events,...

Published
August 31, 2026
Last Modified
August 31, 2026

🔗 CVE IDs covered (1)

📋 Description

@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring.

🔗 References (4)