Sub:jugation – Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers

Executive Summary Astrix Security Research has discovered a new vulnerability class affecting GitHub Actions, GitLab CI, and Terraform Cloud, which we’re calling “Sub:jugation“. By abusing the global OIDC issuer model that all three platforms share, an attacker can assume cloud IAM roles that were configured by (and intended for) entirely different organizations and repositories. The … Continue reading Sub:jugation – Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers