frontdoor rule · FD002

AWS OIDC audience claim not restricted

The audience claim is not what it should be

Amazon Web Services, Google Cloud, Microsoft AzureUpdated Source on GitHub

Severity: contextual, and deliberately not a flat critical.

Situation Severity
No audience condition and no subject condition critical
No audience condition, subject is org-wide high
No audience condition, subject is exact medium

What it means

An OIDC token carries an aud claim naming who the token is for. Checking it stops a token minted for some other relying party being replayed at your cloud.

Why the severity is contextual

On GitHub Actions the workflow chooses its own audience. That makes aud a label rather than a barrier there: anyone who can get a token can get one with any audience they like. The claim that actually constrains something is sub.

So a policy with an exact sub and no aud is a hardening gap, not an open door — and reporting it as critical alongside a genuinely wide-open trust would train people to ignore the word. With no subject condition either, any token that issuer ever minted is accepted, and that is critical.

Cloud differences that matter

GCP: an empty allowedAudiences is the secure default. When it is empty the audience becomes the provider's own canonical resource name, which is specific to that provider. frontdoor does not fire on it. It fires on a custom audience not tied to the provider — a value some other relying party might also accept.

Azure: the audience is fixed by the platform. Entra ID only issues exchange tokens for api://AzureADTokenExchange. Any other value means the credential was configured for a different system, or copied from one.

How to fix it

AWS — take the audience from the provider's registered client IDs, which are in identity_providers[].audiences in the JSON output:

jsonc
"StringEquals": { "token.actions.githubusercontent.com:aud": "sts.amazonaws.com" }

GCP — remove the custom audience and let the default apply.

Azure — set audiences to ["api://AzureADTokenExchange"].

frontdoor answers this once, when you run it; Secorvia checks it continuously across every account you connect, on a free tier that needs no card.