AWS cdk: CDK v2 security: warn against deploying untrusted cloud assemblies
Summary
Added guidance in the CDK security best-practices topic stating that cloud assemblies (the cdk.out directory) can be deployed from external sources, and that you should only deploy a cloud assembly you produced yourself or that comes from a trusted source.
Security assessment
Documents a real supply-chain risk (deploying an attacker-supplied synthesized template/artifact), recommending trust boundaries for cloud assemblies; it is general hardening guidance rather than remediation of a named vulnerability or CVE, so it counts as security documentation.
Evidence
+Similarly, you should not deploy cloud assemblies from sources that you do not trust. Synthesizing a CDK app produces a cloud assembly (the `cdk.out` directory by default). It’s possible to deploy a previously synthesized cloud assembly from a different source; for example, `cdk deploy --app /downloaded/file/path/cdk.out`. Only deploy a cloud assembly that you produced yourself or that comes from a trusted source.
Diff
diff --git a/cdk/v2/guide/security.md b/cdk/v2/guide/security.md index 42fd7ed8f..216a6032e 100644 --- a//cdk/v2/guide/security.md +++ b//cdk/v2/guide/security.md @@ -38,0 +39,2 @@ You should not use CDK in an environment where untrusted authors write parts of +Similarly, you should not deploy cloud assemblies from sources that you do not trust. Synthesizing a CDK app produces a cloud assembly (the `cdk.out` directory by default). It’s possible to deploy a previously synthesized cloud assembly from a different source; for example, `cdk deploy --app /downloaded/file/path/cdk.out`. Only deploy a cloud assembly that you produced yourself or that comes from a trusted source. +