Collected research
Hacking AWS Cognito Misconfigurations
A login-only application exposed its AWS Cognito app client and pool identifiers in the client-side JavaScript SDK, and Cognito still permitted self sign-up. The new account's token minted temporary AWS credentials with full Lambda rights, so rewriting a Lambda function to print its environment variables leaked privileged keys and led to account takeover.
Record
- Researcher
- Sunil Yadav
- Published by
- NotSoSecure
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Sunil Yadav, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .