Loading vulnerability details…
CVSS v3.1
6.3
CVSS v4.0
5.3
EPSS
0.46%
Published
Nov 8, 2024
Modified
Oct 14, 2025
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LWeaknesses (CWE)
Affected Products (1)
References (3)