Amplified exposure: How AWS flaws made Amplify IAM roles vulnerable to takeover
ID: 80f96031-3e0b-57b9-bdeb-0e8e81737ce3
STIX ID: report--80f96031-3e0b-57b9-bdeb-0e8e81737ce3
Feed Name: Datadog Security Labs
Datadog Security Research disclosed two Amplify-related vulnerabilities (including CLI CVE-2024-28056) that caused Cognito-associated IAM roles to be misconfigured and assumable by anyone: one variant arose when Amplify removed the auth component and stripped the role Condition, and the other was an older default trust policy. The report details how attackers could use an attacker-controlled Cognito identity pool and sts:AssumeRoleWithWebIdentity to obtain short-lived credentials, describes discovery and scale (thousands of exposed role ARNs), provides a timeline of coordinated disclosure and AWS mitigations (Amplify fixes and STS protections), and offers detection and remediation steps for affected customers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
