logo
welcome
Wired

Wired

An AWS Configuration Issue Could Expose Thousands of Web Apps

Wired
Summary
Nutrition label

81% Informative

A vulnerability related to Amazon Web Service's traffic-routing service could have been exploited by an attacker to bypass access controls and compromise web applications.

The flaw stems from a customer implementation issue, meaning it isn't caused by a software bug.

Researchers from the security firm Miggo found that, depending on how Application Load Balancer authentication was set up, an attacker could potentially manipulate its handoff to a third -party corporate authentication service to access the target web application and view or exfiltrate data.