CVE-2024-52311

Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired.
Configurations

No configuration.

History

12 Nov 2024, 13:56

Type Values Removed Values Added
Summary
  • (es) Los tokens de autenticación emitidos a través de Cognito en data.all no se invalidan al cerrar la sesión, lo que permite que el usuario previamente autenticado continúe con la ejecución de solicitudes API autorizadas hasta que el token caduque.

09 Nov 2024, 02:15

Type Values Removed Values Added
References
  • () https://github.com/data-dot-all/dataall/security/advisories/GHSA-p69m-h9rw-584v -

09 Nov 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-09 01:15

Updated : 2024-11-12 13:56


NVD link : CVE-2024-52311

Mitre link : CVE-2024-52311

CVE.ORG link : CVE-2024-52311


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization