AWS CodeBuild Webhook Filter Misconfiguration Affects Multiple Repositories
AWS CodeBuild webhook filters in four open-source repositories (aws-sdk-js-v3, aws-lc, amazon-corretto-crypto-provider, awslabs/open-data-registry) had insufficient regex patterns, potentially allowing unauthorized actor IDs to gain admin access. Security researchers demonstrated the vulnerability through an empty commit with no actual impact. No customer action required—this was a project-specific misconfiguration, not a CodeBuild service flaw.
source: [aws/security-bulletin]