CVE-2024-52311
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Nov 9, 2024
Updated: Nov 12, 2024
CWE ID 863
Summary
CVE-2024-52311 is a cybersecurity vulnerability affecting Amazon Cognito's authentication process. When a user logs out, the authentication tokens issued via the 'data.all' endpoints in Cognito are not immediately invalidated. This allows a previously authenticated user to continue making authorized API requests until the token expires. This issue could potentially lead to unauthorized access to protected resources. Organizations using Amazon Cognito are advised to update their configurations to ensure tokens are promptly revoked upon logout.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.