CVE-2024-52311 - CERT CVE
ID CVE-2024-52311
Sažetak Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired.
Reference
CVSS
Base: 6.3
Impact: 3.4
Exploitability:2.8
Pristup
VektorSloženostAutentikacija
NETWORK LOW LOW
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW LOW
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Zadnje važnije ažuriranje 12-11-2024 - 13:56
Objavljeno 09-11-2024 - 01:15