Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-45840 | Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired. |
Solution
A fix for this issue is available in data.all version 2.6.1 and later. Customers are advised to upgrade to version 2.6.1 or later.
Workaround
No workaround given by the vendor.
Tue, 14 Oct 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 |
Tue, 14 Oct 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-613 |
Tue, 14 Oct 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 19 Sep 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Amazon
Amazon data.all |
|
CPEs | cpe:2.3:a:amazon:data.all:*:*:*:*:*:*:*:* | |
Vendors & Products |
Amazon
Amazon data.all |
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 12 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 09 Nov 2024 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Sat, 09 Nov 2024 01:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired. | |
Title | data.all does not invalidate authentication token upon user logout | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2025-10-14T19:25:04.120Z
Reserved: 2024-11-06T21:02:34.355Z
Link: CVE-2024-52311

Updated: 2024-11-12T15:18:44.982Z

Status : Modified
Published: 2024-11-09T01:15:04.133
Modified: 2025-10-14T20:15:32.170
Link: CVE-2024-52311

No data.

No data.