Bug 1623095 (CVE-2018-15869)

Summary: CVE-2018-15869 awscli: Allows loading of an undesired AMI by setting similar image properties
Product: [Other] Security Response Reporter: Andrej Nemec <anemec>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abhgupta, bperkins, chahudso, dbaker, extras-orphan, jokerman, kevin, me, oalbrigt, sthangav, trankin
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-10-05 09:25:05 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1623096, 1623097    
Bug Blocks: 1623098    

Description Andrej Nemec 2018-08-28 13:06:35 UTC
The Amazon Web Services (AWS) CLI version 1.15.85 (and possibly earlier versions) does not require the --owners flag when describing images, which makes it easier for remote attackers to trigger the loading of an undesired AMI by setting similar image properties (i.e., name), as exploited in the wild during August 2018 with a Monero miner AMI instead of the expected Ubuntu AMI.

References:

https://github.com/hashicorp/packer/issues/6584

Comment 1 Andrej Nemec 2018-08-28 13:06:59 UTC
Created awscli tracking bugs for this issue:

Affects: fedora-all [bug 1623096]

Comment 2 Andrej Nemec 2018-08-28 13:07:11 UTC
Created awscli tracking bugs for this issue:

Affects: fedora-all [bug 1623096]

Comment 4 Riccardo Schirone 2018-10-05 09:25:05 UTC
Closing this bug as NOTABUG and asked MITRE for rejection, since the issue does not seem to be in AWS CLI but in Packer.