Amazon Linux AMI : aws-cfn-bootstrap (ALAS-2017-866)

high Nessus Plugin ID 102208

Synopsis

The remote Amazon Linux AMI host is missing a security update.

Description

A vulnerability was reported in the CloudFormation bootstrap tools, where default behavior in the handling of cfn-init metadata can provide escalated privileges to an attacker with local access to the system

Solution

Run 'yum update aws-cfn-bootstrap' to update your system.

Update the AWS::CloudFormation::Init metadata section of your template, specifically the entries listed under the 'files' key, to explicitly specify the mode field as documented. We recommend setting the mode to explicitly disable permissions for non-owners.
Alternatively, you can also choose to explicitly change the mode of the files listed in your template, by directly logging on to the instance.

Restart the cfn-hup process

See Also

https://access.redhat.com/security/cve/CVE-Pending

https://alas.aws.amazon.com/ALAS-2017-866.html

Plugin Details

Severity: High

ID: 102208

File Name: ala_ALAS-2017-866.nasl

Version: 3.4

Type: local

Agent: unix

Published: 8/7/2017

Updated: 4/18/2018

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:aws-cfn-bootstrap, cpe:/o:amazon:linux

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Patch Publication Date: 8/3/2017

Reference Information

ALAS: 2017-866