Skip to content

H3-2022-0076

Unauthenticated AWS Cognito Role

Category SECURITY_MISCONFIGURATION
Base Score 2.6

Description

An AWS Cognito identity pool is allowing unauthenticated users to retrieve IAM role credentials.

Impact

Anyone with access to the Cognito Identity Pool ID can generate AWS keys for the Identity Pool's baseline ('unauthenticated') IAM role. An attacker could potentially use these AWS keys to read sensitive information or perform destructive actions, depending on the role's permissions.

References