H3-2022-0076
Unauthenticated AWS Cognito Role
Category | SECURITY_MISCONFIGURATION |
Base Score | 2.6 |
Description
An AWS Cognito identity pool is allowing unauthenticated users to retrieve IAM role credentials.
Impact
Anyone with access to the Cognito Identity Pool ID can generate AWS keys for the Identity Pool's baseline ('unauthenticated') IAM role. An attacker could potentially use these AWS keys to read sensitive information or perform destructive actions, depending on the role's permissions.