mediumVulnerability

GHSA-gfp8-mp24-5vxg

Impact: @hulumi/baseline versions before 1.3.2 could miss some CloudTrail event-selector tampering evidence, reducing coverage for changes to audit logging configuration. Patched in 1.3.2: detection coverage and regression tests were expanded. Remediation: upgrade @hulumi/baseline to 1.3.2 or later and rerun affected previews/checks.

Properties

ghsa_id
GHSA-gfp8-mp24-5vxg
severity
medium
summary
@hulumi/baseline: CloudTrail selector tampering events were not fully detected
cve_id
GHSA-gfp8-mp24-5vxg
is_ghsa_only
true
ghsa_published
2026-05-21T20:43:27Z
source_url
https://github.com/advisories/GHSA-gfp8-mp24-5vxg
ghsa_updated
2026-05-21T20:43:28Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/@hulumi/baseline

AFFECTS (1)

[Software]npm/@hulumi/baseline

HAS_WEAKNESS (1)

[Weakness]Insufficient Logging

Explore deeper with Ninja Signal's threat intelligence graph