CVE-2024-52311

Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired.
Configurations

Configuration 1 (hide)

cpe:2.3:a:amazon:data.all:*:*:*:*:*:*:*:*

History

14 Oct 2025, 20:15

Type Values Removed Values Added
CWE CWE-863 CWE-613

14 Oct 2025, 19:15

Type Values Removed Values Added
References
  • () https://github.com/data-dot-all/dataall/releases/tag/v2.6.1 -

19 Sep 2025, 14:17

Type Values Removed Values Added
CPE cpe:2.3:a:amazon:data.all:*:*:*:*:*:*:*:*
First Time Amazon
Amazon data.all
References () https://aws.amazon.com/security/security-bulletins/AWS-2024-013 - () https://aws.amazon.com/security/security-bulletins/AWS-2024-013 - Vendor Advisory
References () https://github.com/data-dot-all/dataall/security/advisories/GHSA-p69m-h9rw-584v - () https://github.com/data-dot-all/dataall/security/advisories/GHSA-p69m-h9rw-584v - Vendor Advisory

Information

Published : 2024-11-09 01:15

Updated : 2025-10-14 20:15


NVD link : CVE-2024-52311

Mitre link : CVE-2024-52311

CVE.ORG link : CVE-2024-52311


JSON object : View

Products Affected

amazon

  • data.all
CWE
CWE-613

Insufficient Session Expiration