aws-cdk-lib is vulnerable to Incorrect Execution-Assigned Permissions
21
Low Risk
Affected versions of this package are vulnerable to incorrect permission assignment when using Aspects with the default execution order. An attacker can assign DEFAULT permissions to a custom Aspect, which may be overridden by a built-in CDK method using MUTATING permissions. This can cause the custom Aspect to have either fewer or, in permissive environments, more permissions than expected.
You are affected if you are using a version that falls within the vulnerable range.
aws-cdk-lib is vulnerable to Incorrect Execution-Assigned Permissions in versions 2.0.0 - 2.189.0.
Upgrade the aws-cdk-lib library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant