Web Hack List

Collected research

Hacking AWS Cognito Misconfigurations

A login-only application exposed its AWS Cognito app client and pool identifiers in the client-side JavaScript SDK, and Cognito still permitted self sign-up. The new account's token minted temporary AWS credentials with full Lambda rights, so rewriting a Lambda function to print its environment variables leaked privileged keys and led to account takeover.

Record

Researcher
Sunil Yadav
Published by
NotSoSecure
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Sunil Yadav, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .