• Our channels:
  • Chief IT
  • Space
  • Smart Cities
  • Drones & Robotics
  • Video Systems
  • Australian Cyber
  • Australian Security
  • Asia Pacific
  • Southeast Asia
  • Podcast
  • MySec.TV
  • Best in Tech
  • MySmartTech
Cyber Risk Leaders
Navigate
  • Cyber Risk Leaders
  • News
    • Featured
    • Cyber Resilience
    • Editor’s Desk
    • Education
    • TechTime
    • Women in Security
  • Contributors
  • Magazines
  • Events
  • RESOURCES
  • TRAINING
  • Shop
  • Advertise
  • Subscribe

Cross-Account Access Vulnerability on AWS SageMaker Jupiter Notebook Instance

0
By Cyberriskleaders on December 3, 2021 Data Breach, IT solutions, vulnerabilities

Lightspin has announced the discovery of a cross-account access vulnerability discovered in AWS’s SageMaker Jupyter Notebook Instance.

Lightspin’s research team found this vulnerability as part of its ongoing research into security in data science tools. The team investigated Amazon’s SageMaker which is a fully managed machine learning (ML) service in AWS.

Amazon SageMaker helps data scientists and developers to prepare, build, train, and deploy high-quality machine learning (ML) models quickly by bringing together a broad set of capabilities purpose-built for ML. SageMaker launched in 2017 and is used by some of the world’s leading global enterprises, meaning any discovery of areas of exploitation could have widespread impact.

The research team investigated the potential vulnerabilities that could be attached to Amazon’s SageMaker, and more specifically the Jupyter Notebook Instances. During their research, the team found that potential attackers had been able to run any code on an AWS SageMaker Jupyter Notebook Instance across accounts.

This allowed them to access the Notebook Instance metadata endpoint and steal access tokens for the attached role. Using the access token, the attacker could have read data from S3 buckets, created VPC endpoints, and taken more potentially harmful actions that were allowed by the SageMaker execution role and the “AmazonSageMakerFullAccess” policy.

Since the discovery of this vulnerability, the Lightspin team contacted the AWS Security team to alert them of the findings. As of this writing, the vulnerability has since been remediated.

“It is nearly impossible for a company to have complete security control when a single app flaw can leave a door open to cyberattacks,” said Gafnit Amiga, Director of Research at Lightspin. “We believe in advanced research of managed services in order to enhance the product’s detection capabilities and to improve the resilience of the cloud providers for everyone.”

Share. Twitter Facebook Pinterest LinkedIn Tumblr Email

Related Posts

  • Featured | IT solutions | Miscellaneous | Movers & Shakers | May 8, 2025

    Bugcrowd Joins AWS Independent Software Vendor Accelerate Program

  • Artificial Intelligence | Featured | IT solutions | Security Products | May 7, 2025

    Trend Micro Unveils New AI-Powered Threat Detection Capabilities

  • Cyber Resilience | Featured | IT solutions | May 2, 2025

    Intercede’s MyID CMS Upgrades Enterprise Security

  • Follow us

    Visit Us On TwitterVisit Us On FacebookVisit Us On YoutubeVisit Us On Linkedin

ENJOY OUR OTHER CHANNELS

  • A dedicated channel for Boards, C-Suite Executives and Cyber Risk Leaders to highlight cyber threats as a key business issue.

    MySecurity Media Pty Limited
    ABN 54 145 849 056
    A: GPO Box 930 Sydney NSW 2001
    E: promoteme@mysecuritymedia.com
    W: www.mysecuritymedia.com

  • NETWORK

    • Marketplace
    • Community
    • Contributors
    • Lead Publication
    • Promote Your Brand
    • Privacy Policy
  • NEWS

    • Featured
    • Cyber Resilience
    • Editor’s Desk
    • Education
    • TechTime
    • Women in Security
  • DOWNLOAD APP

  • EVENTS
    > Find a Speaker
    > New Arrivals
    > Upcoming Events
    > Past Events
    > Register an Event
  • RESOURCES
    > Reports
    > Whitepapers
    > Research
    > Books
    > COVID 19 Resources
    > Magazines
    > Podcasts
    > MySecurity TV
    > Australia in Space TV
  • PRODUCTS
    > Solution Products
    > Online Store
    > TeePublic Store
    > Promote Your Brand

    TRAINING
    > Courses
    > Webinars – Live
    > Webinars – On Demand
    > Learn Security Platform
  • COMMUNITY
    > Indo-Pacific Space and Earth Network
    > Space and Earth - Partners and Advisory
    > IPRAAC
    > IPSEC
    > Security & Risk Professional Insight Series
    > Women in Security Awards
    > Partners
    > Speakers
    > Providers
    > Promote Your Brand
  • NEWS CHANNELS
    > MySec.TV
    > Australia in Space TV
    > Cyber Security Weekly Podcast
    > Cyber Risk Leaders
    > Chief IT
    > Drones & Robotics
    > Space & Defense
    > Australia in Space
    > Smart Cities Tech
    > Video Systems
    > Asia Pacific Security Magazine
    > ASEAN Technology & Security
    > Australian Cyber Security Magazine
    > Australian Security Magazine

© My Security Media. All Right Reserved 2019.   Privacy Policy | Terms & Conditions | Competition T&Cs