interesting · Cloud privilege
A SageMaker project contributor can execute commands in another member’s Studio Space and take that member’s temporary role credentials.
Affects
Amazon SageMaker Distribution images used by SageMaker Unified Studio Spaces in AWS.
Crafted project connection data reaches an unneutralized shell invocation when another member’s Space validates connections during startup.
Detail and 2 sources
The injected command runs in the peer’s Space; when Trusted Identity Propagation is enabled, it can obtain that member’s temporary execution-role credentials for downstream AWS calls.