Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 09 Nov 2024 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Sat, 09 Nov 2024 01:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired. | |
Title | data.all does not invalidate authentication token upon user logout | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: AMZN
Published: 2024-11-09T00:42:49.246Z
Updated: 2024-11-12T15:18:52.220Z
Reserved: 2024-11-06T21:02:34.355Z
Link: CVE-2024-52311
Vulnrichment
Updated: 2024-11-12T15:18:44.982Z
NVD
Status : Awaiting Analysis
Published: 2024-11-09T01:15:04.133
Modified: 2024-11-12T13:56:54.483
Link: CVE-2024-52311
Redhat
No data.