Vulnerability Description
Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amazon | Data.All | >= 1.0.0, < 2.6.1 |
Related Weaknesses (CWE)
References
- https://aws.amazon.com/security/security-bulletins/AWS-2024-013Vendor Advisory
- https://github.com/data-dot-all/dataall/releases/tag/v2.6.1
- https://github.com/data-dot-all/dataall/security/advisories/GHSA-p69m-h9rw-584vVendor Advisory
FAQ
What is CVE-2024-52311?
CVE-2024-52311 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired.
How severe is CVE-2024-52311?
CVE-2024-52311 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-52311?
Check the references section above for vendor advisories and patch information. Affected products include: Amazon Data.All.