CVE advisoryCRITICAL
CVE-2024-28056
Amazon AWS Amplify CLI IAM Role Trust Policy Misconfiguration Leads to Unauthorized Access
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
Amazon AWS Amplify CLI may misconfigure IAM role trust policies when an Authentication component is removed, potentially allowing unauthorized access to AWS resources if used between August 2019 and January 2024.