Collected research
AWS AppSync: A Case Study in Confused Deputy Vulnerabilities
Shows a cross-account confused-deputy flaw in AWS AppSync. Request properties were accepted case-insensitively, but the same-account role check only recognized serviceRoleArn's normal casing; a differently cased key let an attacker's AppSync data source assume a victim IAM role that trusted the service and call the role's permitted AWS APIs.
Record
- Researcher
- Nick Frichette and @datadoghq
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Nick Frichette and @datadoghq, first published at the original source. Preserved copies are kept so the citation survives its host.