VYPR

AWS Plugin

by Openbao

CVEs (1)

  • CVE-2025-59048HigOct 23, 2025
    risk 0.46cvss 8.1epss 0.00

    OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable to cross-account IAM role Impersonation in the AWS auth method. The vulnerability allows an IAM role from an untrusted AWS account to authenticate by…