https://orca.security/resources/blog/aws-glue-vulnerability/ * English * Contact * Support * Login Orca SecurityOrca Security Orca SecurityOrca Security * Platform + Back Platform Cloud Security Platform o [svg][icon-nav-s]SideScanning(tm) TechnologyComplete cloud coverage without agents o [svg][icon-nav-c]Context-Aware SecurityPrioritize the 1% of alerts that matter o [svg][icon-nav-b]Built-in ComplianceContinuous compliance with a single platform o [svg][icon-nav-c]Automation & CustomizationGet actionable intelligence to the right teams * Solutions Back Solutions Solutions by + Threat Type o Back Threat Type Threat Type o # Vulnerability ManagementDiscover and prioritize vulnerabilities in the cloud # Malware DetectionCloud malware detection with no performance impact # MisconfigurationsFix misconfigurations before attackers find them # Lateral Movement RiskExpose hidden lateral movement risk # Identity and Access ManagementDiscover common and obscure IAM misconfigurations # Sensitive Data DetectionLocate misplaced and unprotected sensitive data + Industry o Back Industry Industry o # Financial ServicesAgentless multi-cloud security and compliance at scale # Technology ServicesFlexible multi-cloud security with unlimited visibility # Media & EntertainmentSimplify security and compliance with a single platform * Partners Back Partners [svg][nav-join-t] Become a partner Join the program -> + o Partner OverviewHelping partners across the globe grow their business + o Technology Ecosystem # Amazon Web Services # Microsoft Azure # Google Cloud Platform * About Back About [svg][nav-join-o] Join our team See Open Positions -> + o About UsSecurity built for the cloud o CareersFind your next job at Orca o FAQsAll your Orca questions answered o Rating & ReviewsSee how Orca is rated by your peers + o Orca Research PodAdvancing cloud security o NewsroomOrca Security news and coverage o Media KitOrca Security press materials o Contact UsContact Orca Security * Resources Back Resources Cloud Security Risk AssessmentCloud Security Risk Assessment Orca Security's Free Risk Assessment and Trial Get started today -> + o Resource LibraryOrca videos, reports and white papers o Product InfoOrca product literature and videos o EventsUpcoming Orca events and webinars o PodcastHear from IT security leaders + o BlogExpand your cloud security knowledge o ComparisonsHead-to-head comparison of cloud security solutions o Case StudiesLearn why customers use and trust Orca * * Watch Demo [ ] View more results * Blog * Research Pod Superglue: Orca Security Research Team Discovers AWS Glue Vulnerability [svg][avatar_yan] Yanir Tsarimi Published: Jan 13, 2022 Reading time: 4 Minutes Orca's Research Team discovered a critical vulnerability that could allow an actor to create resources and access data of AWS Glue customers.Orca's Research Team discovered a critical vulnerability that could allow an actor to create resources and access data of AWS Glue customers. * * * * The cloud environment relies on a few core principles. One of them is the idea that each customer is isolated from other customers, and no data can be inadvertently accessed across accounts. As the Internet moves more and more to the cloud, the importance of cloud security becomes increasingly paramount. We, the Orca Security Research Team, discovered a critical security issue in the AWS Glue service that could allow an actor to create resources and access data of other AWS Glue customers. The exploit was a complex multi-step process and was ultimately possible due to an internal misconfiguration within AWS Glue. The Glue service has access to large quantities of data, making it a highly attractive target. [svg][orca_security_aws_superglue_attack_flow] We're sharing this with you today after having worked with AWS to remediate the issue and confirm with AWS that no customer accounts were inappropriately accessed. Within hours of reporting the issue, the AWS Glue service team had reproduced and confirmed our findings. By the following morning, a partial mitigation was deployed globally, followed by a full mitigation a few days later. AWS Principal Engineer, Anthony Virtuoso had this to say about our joint collaborative efforts in discovering and quickly fixing this vulnerability: "At AWS, security is everyone's job and our highest priority. We take vulnerability reports extremely seriously. We spend a lot of time thinking about and implementing security invariants to keep our customers safe, and we appreciate when that work can be informed or improved by independent security research." Anthony continued, "Today, Orca Security, a valued AWS partner, helped us detect and mitigate a misconfiguration before it could impact any customers. We greatly appreciate their talent and vigilance, and we would like to thank them for the shared passion of protecting AWS customers through their findings." Technical Overview of the Superglue Zero-Day Vulnerability AWS Glue is a serverless data integration service that makes it easy to discover, prepare, and combine data for analytics, machine learning, and application development. During our research, we were able to identify a feature in AWS Glue that could be exploited to obtain credentials to a role within the AWS service's own account, which provided us full access to the internal service API. In combination with an internal misconfiguration in the Glue internal service API, we were able to further escalate privileges within the account to the point where we had unrestricted access to all resources for the service in the region, including full administrative privileges. [svg][blog_AWSsuperglue_Admin] [svg][blog_AWSsuperglue_roles-1] By carefully looking at what data could be accessible in the service account, we confirmed that we would be able to access data owned by other AWS Glue customers. We used accounts under our control to test and verify that this issue gave us the ability to access data from our other accounts without affecting any other AWS customers' data. These are some of the things that we were able to do: 1. Assume roles in AWS customer accounts that are trusted by the Glue service. In every account that uses Glue, there's at least one role of this kind. 2. Query and modify AWS Glue service-related resources in a region. This includes but is not limited to metadata for: Glue jobs, dev endpoints, workflows, crawlers and triggers. As mentioned above, all research related to this finding was conducted within AWS accounts owned by Orca Security. No other AWS customer accounts and no other customers' data was accessed during our research. We would like to thank the AWS security team, specifically Dan Urson and Zack Glick, for collaborating with us and working to quickly confirm and resolve this issue. The process of reporting and having the issue resolved was smooth and we got to meet some of the great people at AWS that help make sure the cloud is secure. The Orca Security Research Team continues to dig around different cloud products and services to find such zero-day vulnerabilities. Our goal is to discover these vulnerabilities before any malicious actors do. If you'd like to learn more about Orca Security I invite you to experience our tech and talent first-hand with a no-obligation, free cloud risk assessment. You'll get complete visibility into your public cloud, a detailed risk report with an executive summary, and time with our cloud security experts. * [svg][icon_vulne] Discover Your Cloud Vulnerabilities In Minutes Scan your entire AWS, Azure, and Google Cloud environments for vulnerabilities with Orca Security's free, no obligation risk assessment. TAKE FREE RISK ASSESSMENT Yanir Tsarimi is a Cloud Security Researcher at Orca Security. Follow him on Twitter @Yanir_ * * * * [svg][avatar_yan] Yanir Tsarimi * * * * Stay in the loop Keep up to date with everything you need to know about cloud security and our latest research By submitting my email address you agree to the use of my personal data in accordance with Orca Security Privacy Policy. Related articles The Orca Security Research Team found multiple critical zero-day cloud vulnerabilities including two on AWS: Superglue and BreakingFormation.The Orca Security Research Team found multiple critical zero-day cloud vulnerabilities including two on AWS: Superglue and BreakingFormation. Blog Two Critical Cloud Vulnerabilities to Convince You to Move to the Cloud Read now Orca Security's vulnerability researcher, Tzah Pahima, discovered a zero day AWS CloudFormation vulnerability, which AWS quickly mitigated within 6 days.Orca Security's vulnerability researcher, Tzah Pahima, discovered a zero day AWS CloudFormation vulnerability, which AWS quickly mitigated within 6 days. Blog BreakingFormation: Orca Security Research Team Discovers AWS CloudFormation Vulnerability Read now See Orca in actionSee Orca in action See Orca in action-> View a 10 minute recorded demo or sign up for a personalized one-on-one walk-through. * Platform + CLOUD SECURITY PLATFORM o SideScanning(tm) Technology o Context-Aware Security o Built-in Compliance o Automation & Customization + TECHNOLOGY ECOSYSTEM o Amazon Web Services o Microsoft Azure o Google Cloud Platform * Solutions + By Threat Type o Vulnerability Management o Malware Detection o Misconfigurations o Lateral Movement Risk o IAM Risk o Sensitive Data Detection + By Industry o Financial Services o Technology Services o Media & Entertainment * Resources + Resources o Library o Product Info o Podcast o Case Studies o Blog o Events + COMPARISONS o Cloud Security Posture Managers (CSPM) o Prisma Cloud Security o Qualys Cloud Agent o Twistlock Container Security o Redlock Palo Alto o Rapid7 InsightVM o Check Point CloudGuard Dome9 * Company + Company o About o Partners o Reviews o Careers o Newsroom o Media Kit o FAQs + Contact o Support o Login * Stay in touch Get cloud security insights and the latest Orca news + [svg][footer_bad] + [svg][footer_bad] + [svg][footer_bad] --------------------------------------------------------------------- Orca SecurityOrca Security ©2022 Orca Security. All rights reserved. * Privacy Policy * Terms of Use * * * *