frontdoor rule · FD002
AWS OIDC audience claim not restricted
The audience claim is not what it should be
Severity: contextual, and deliberately not a flat critical.
| Situation | Severity |
|---|---|
| No audience condition and no subject condition | critical |
| No audience condition, subject is org-wide | high |
| No audience condition, subject is exact | medium |
What it means
An OIDC token carries an aud claim naming who the token is for. Checking it
stops a token minted for some other relying party being replayed at your cloud.
Why the severity is contextual
On GitHub Actions the workflow chooses its own audience. That makes aud a
label rather than a barrier there: anyone who can get a token can get one with
any audience they like. The claim that actually constrains something is sub.
So a policy with an exact sub and no aud is a hardening gap, not an open
door — and reporting it as critical alongside a genuinely wide-open trust would
train people to ignore the word. With no subject condition either, any token
that issuer ever minted is accepted, and that is critical.
Cloud differences that matter
GCP: an empty allowedAudiences is the secure default. When it is empty the
audience becomes the provider's own canonical resource name, which is specific
to that provider. frontdoor does not fire on it. It fires on a custom
audience not tied to the provider — a value some other relying party might also
accept.
Azure: the audience is fixed by the platform. Entra ID only issues exchange
tokens for api://AzureADTokenExchange. Any other value means the credential
was configured for a different system, or copied from one.
How to fix it
AWS — take the audience from the provider's registered client IDs, which
are in identity_providers[].audiences in the JSON output:
"StringEquals": { "token.actions.githubusercontent.com:aud": "sts.amazonaws.com" }GCP — remove the custom audience and let the default apply.
Azure — set audiences to ["api://AzureADTokenExchange"].
frontdoor answers this once, when you run it; Secorvia checks it continuously across every account you connect, on a free tier that needs no card.