🔶🔷🔴 The Two Mitigations for the Service-Account Confused Deputy in the Cloud
Two mitigations exist for cloud service-account confused deputy attacks: for customer-managed identities, an attachment gate (GCP actAs, AWS iam:PassRole, Azure assign/action) controls bind-time authorization; for provider-managed identities, the CSP enforces internal checks, with AWS uniquely exposing this via Forward Access Sessions and condition keys.
https://kattraxler.cloud/the-two-mitigations-for-the-service-account-confused-deputy-in-the-cloud
#aws #azure #gcp
Post #1507
397

- ❤ 1
- 👍 1
- 🔥 1