T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:147- Finding
Wildcard COS Policy Grants Excessive Cloud Privileges
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:147-149
Vulnerability Type:T05: Unauthorized Access and Privilege Escalation
Risk Level: HighVulnerable Code:
json "action": [ "name/cos:*" ], "resource": "*"Technical Analysis
The documented access policy grants every Tencent Cloud COS action against every COS resource available to the configured sub-user. This violates least privilege and contradicts the document's recommendation to use minimal permissions.
The wildcard action can authorize security-sensitive and destructive operations beyond ordinary object upload and download, including bucket administration, ACL changes, lifecycle configuration, object deletion, and bucket deletion, subject to Tencent Cloud's policy evaluation rules. The wildcard resource scope applies those permissions across all matching COS resources in the account rather than limiting access to explicitly approved buckets or object prefixes.
Attack Path
- A user follows the Skill documentation and creates a sub-user policy containing
name/cos:*over*. - The resulting secret ID and secret key are configured for the Skill.
- An attacker obtains those credentials through host compromise, accidental
.envexposure, malicious local code, or another credential leak. - The attacker authenticates directly to Tencent Cloud COS using the exposed credentials.
- The attacker invokes COS operations against any resource covered by the wildcard policy, rather than being limited to the bucket and operations required by the intended workflow.
- Depending on account resources and Tencent Cloud policy evaluation, the attacker can read, overwrite, expose, reconfigure, or delete COS data.
Impact Assessment
Compromise of the configured credentials may provide account-wide COS access. Potential impact includes:
- Confidentiality loss through unauthorized object listing and download.
- Integrity loss ...[truncated 431 chars]
- A user follows the Skill documentation and creates a sub-user policy containing
- Remediation
View remediation
Remediation Suggestions
- Replace
name/cos:*with an explicit list of operations required for each supported workflow. - Scope
resourceto approved bucket and object resource identifiers instead of*. - Publish separate policy templates for:
- Read-only object access.
- Upload and download access.
- Lifecycle administration.
- Bucket creation and deletion.
- Keep ACL modification, object deletion, lifecycle expiration, bucket clearing, and bucket deletion disabled unless explicitly required.
- Use object-prefix restrictions where workloads only need access to a particular namespace.
- Use separate short-lived credentials for administrative and routine object operations where supported.
- Add explicit policy review and credential-rotation guidance, and ensure the documented policy matches the claim of least privilege.
- Replace
