Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 12 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 09 Nov 2024 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 09 Nov 2024 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired. | |
| Title | data.all does not invalidate authentication token upon user logout | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published: 2024-11-09T00:42:49.246Z
Updated: 2024-11-12T15:18:52.220Z
Reserved: 2024-11-06T21:02:34.355Z
Link: CVE-2024-52311
Updated: 2024-11-12T15:18:44.982Z
Status : Awaiting Analysis
Published: 2024-11-09T01:15:04.133
Modified: 2024-11-12T13:56:54.483
Link: CVE-2024-52311
No data.