Permission Denied
229 incident problems that show up as “Permission Denied”.
먼저 읽을 가이드
추천 문제
All problems (229)
SECURITY-092Cloud WAF blocks the admin API path only after a new JSON field increases rule score above thresholdThe endpoint worked before, but the updated payload shape now trips a scoring-based rule model that was previously below the block threshold.SecurityAdvanced17 minProSECURITY-102Just-in-time admin approval succeeds, but the bastion PAM cache still enforces the previous group membershipOperators receive the right entitlement in the identity plane, yet the bastion keeps denying access until its local authorization cache expires.SecurityAdvanced17 minProSECURITY-318A backup or snapshot path is readable while cross-account or cross-region recovery still lacks the exact decrypt or restore permission it needs during a failover rehearsalThe artifact exists and the recovery scope where it matters is still unauthorized. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-234A backup snapshot restores while the copy role still lacks the right to re-encrypt in the target account during a failover rehearsalDisaster recovery looks viable until the protected copy has to become live elsewhere. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-180A cloud permission exists in one region while the recovery workflow executes in another scope during a failover rehearsalThe right grant is present and absent at the same time depending on where the workflow actually runs. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-124A presigned URL is valid, but the CDN cache key ignores one scoping parameter and content becomes reusable outside the intended request contextObject access control is strong at origin, yet the edge cache weakens it by collapsing distinct authorization contexts.SecurityAdvanced18 minProCICD-142A reusable workflow updates its permissions block, but the caller workflow still downgrades the token scope and deployment cannot assume the cloud roleThe shared workflow looks fixed, yet the effective identity is still too narrow because the caller constrains it further.CI/CDAdvanced18 minProSECURITY-104A rotated KMS key policy omits the legacy alias and historical backup decrypt operations fail during recoveryNew encrypt operations work, but restore testing fails because the recovery path still references an alias that the new policy no longer permits.SecurityAdvanced18 minProSECURITY-282A trust policy validates the new OIDC issuer while one condition key still matches the old claim path during a failover rehearsalThe provider migration is half-complete and federated access still fails on the detail that matters. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-210An authorization token is valid for one delivery host while the content path crosses into another during a failover rehearsalAuthorization is scoped correctly and the asset path does not stay where the token applies. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProCICD-110Argo CD ignoreDifferences hides drift in service account annotations and the workload loses cloud identity on syncGit and cluster appear in sync, yet the runtime identity broke because a diff-ignore rule masked the exact annotation that binds the pod to its cloud role.CI/CDAdvanced18 minProCICD-094Argo CD sync succeeds but a namespace label policy silently strips the network exemption labelThe app is deployed cleanly, yet the workload breaks because a cluster policy rewrites the namespace labels the app depends on for networking.CI/CDAdvanced18 minProSECURITY-111CloudTrail shows the access denies, but the missing service-linked role auto-creation was never logged in the regional trail you checkedThe permissions symptom is real, yet the causal event lives in a different audit scope than the one the team has been searching.SecurityAdvanced18 minProSECURITY-078JIT provisioning creates duplicate accounts after the immutable identity key changesFederation remains healthy, but every login now spawns another local account because the stable identity key changed from email to a new immutable identifier.SecurityAdvanced18 minProCICD-102OIDC exchange fails only in reusable workflowsA shared workflow refactor succeeds for linting but deployment breaks because the federated identity provider expects a different token audience than the child workflow emits.CI/CDAdvanced18 minProSECURITY-079Secrets Manager rotation succeeds but the application keeps reading the old current version stageThe rotation Lambda finishes, yet the service still fails login because the stage labels and the consumer refresh path are out of sync.SecurityAdvanced18 minProCICD-113Signing verifies the tarball provenance but deployment consumes an OCI reference that was never attestedThe release report shows a verified artifact, but the runtime image came from a different reference path than the object the signing step covered.CI/CDAdvanced18 minProSECURITY-091SSO works but step-up MFA never triggersPrimary authentication succeeds, yet privileged actions remain exposed because the application is still reading an outdated assurance claim.SecurityAdvanced18 minProSECURITY-139The reverse proxy and WAF normalize duplicate headers differently, creating a request-smuggling edge case on one legacy routeMost paths are safe, but one parsing mismatch keeps a classic multi-hop ambiguity alive.SecurityAdvanced18 minProSECURITY-174Two request-processing layers normalize the same input differently and one legacy route stays bypassable during a failover rehearsalMultiple security layers inspect the request and disagree on what the request really is. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minPro