home.social

#mwaa — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mwaa, aggregated by home.social.

  1. Tenable Research discovered a one-click account takeover vulnerability in the AWS Managed Workflows Apache Airflow service, and that could have resulted in remote code execution (RCE) on the underlying instance, and in lateral movement to other services. Additional research revealed that numerous shared-parent service domains in AWS, Azure and GCP were misconfigured, putting cloud customers at considerable risk. No CVE ID associated. 🔗 tenable.com/blog/flowfixation-

    #FlowFixation #AWS #MWAA #ApacheAirflow #RCE