Back to directory
WRITEUP #1911

A Confused Deputy Vulnerability in AWS AppSync

CloudConfused deputyPrivilege escalation
by@frichette_n(Nick Frichette)
Program
AWS
Published
Nov 21, 2022
Added to HackDex
Nov 22, 2022
Read Full Writeuphttps://securitylabs.datadoghq.com/articles/appsync-vulnerability-disclosure/
RELATED WRITEUPS
Addressed AWS defaults risks: OIDC, Terraform and Anonymous to AdministratorAccess
CloudOIDC
Double Agent: Exploiting Pass-through Authentication Credential Validation in Azure AD
CloudPrivilege escalation
UnOAuthorized: Privilege Elevation Through Microsoft Applications
CloudPrivilege escalation
Escalating Privileges in Google Cloud via Open Groups
CloudPrivilege escalation
ConfusedFunction: A Privilege Escalation Vulnerability Impacting GCP Cloud Functions
CloudPrivilege escalation

Built with ❤️ by Shubham Rawat