CVE-2024-52311

Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired.
Configurations

Configuration 1 (hide)

cpe:2.3:a:amazon:data.all:*:*:*:*:*:*:*:*

History

14 Oct 2025, 20:15

Type Values Removed Values Added
CWE CWE-863 CWE-613

14 Oct 2025, 19:15

Type Values Removed Values Added
References
  • () https://github.com/data-dot-all/dataall/releases/tag/v2.6.1 -

19 Sep 2025, 14:17

Type Values Removed Values Added
First Time Amazon
Amazon data.all
References () https://aws.amazon.com/security/security-bulletins/AWS-2024-013 - () https://aws.amazon.com/security/security-bulletins/AWS-2024-013 - Vendor Advisory
References () https://github.com/data-dot-all/dataall/security/advisories/GHSA-p69m-h9rw-584v - () https://github.com/data-dot-all/dataall/security/advisories/GHSA-p69m-h9rw-584v - Vendor Advisory
CPE cpe:2.3:a:amazon:data.all:*:*:*:*:*:*:*:*

12 Nov 2024, 13:56

Type Values Removed Values Added
Summary
  • (es) Los tokens de autenticación emitidos a través de Cognito en data.all no se invalidan al cerrar la sesión, lo que permite que el usuario previamente autenticado continúe con la ejecución de solicitudes API autorizadas hasta que el token caduque.

09 Nov 2024, 02:15

Type Values Removed Values Added
References
  • () https://github.com/data-dot-all/dataall/security/advisories/GHSA-p69m-h9rw-584v -

09 Nov 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-09 01:15

Updated : 2025-10-14 20:15


NVD link : CVE-2024-52311

Mitre link : CVE-2024-52311

CVE.ORG link : CVE-2024-52311


JSON object : View

Products Affected

amazon

  • data.all
CWE
CWE-613

Insufficient Session Expiration