Skip to content

Commit dcc7e7e

Browse files
mer-bkorniko98
andauthored
Create bedrock-api-logging-issue (#409)
* Create bedrock-api-logging-issue * Update bedrock-api-logging-issue * Update bedrock-api-logging-issue --------- Co-authored-by: Amitai Cohen <[email protected]>
1 parent 5884edc commit dcc7e7e

File tree

1 file changed

+29
-0
lines changed

1 file changed

+29
-0
lines changed
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
title: Bedrock API Logging Issue
2+
slug: bedrock-api-logging-issue
3+
cves: null
4+
affectedPlatforms:
5+
- AWS
6+
affectedServices:
7+
- Amazon Bedrock
8+
- CloudTrail
9+
image: https://images.unsplash.com/photo-1493556273165-cf5bca5cc8e6?ixlib=rb-1.2.1&ixid=MnwxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8&auto=format&fit=crop&w=1173&q=80
10+
severity: Medium
11+
discoveredBy:
12+
name: Alessandro Brucato
13+
org: Sysdig
14+
domain: sysdig.com
15+
twitter: null
16+
publishedAt: 2024/12/12
17+
disclosedAt: 2024/07/17
18+
exploitabilityPeriod: Until 2024/08/09
19+
knownITWExploitation: false
20+
summary: |
21+
Sysdig's Threat Research Team discovered an issue with Amazon Bedrock API logging in CloudTrail. Failed API calls were logged as successful without error codes, hindering detection efforts and potentially generating false positives. The issue affected Bedrock Runtime APIs, specifically InvokeModel and Converse. AWS resolved the problem.
22+
manualRemediation: |
23+
None required
24+
detectionMethods: |
25+
null
26+
contributor: https://github.com/mer-b
27+
entryStatus: Finalized
28+
references:
29+
- https://sysdig.com/blog/bedrock-slip-sysdig-trt-discovers-cloudtrail-logging-missteps/

0 commit comments

Comments
 (0)