Executive brief
AWS CDK is a framework for defining cloud infrastructure using code. When developers use CDK's RestApi construct with Cognito authentication and authorization scopes, a flaw can cause the generated CloudFormation template to grant authenticated users broader access than intended. This could allow users to access or modify API data they should not be able to reach.
Technical details
The vulnerability exists in AWS CDK versions 2.142.0 through 2.148.0 and is classified as incorrect authorization (CWE-863). When the RestApi construct is used with CognitoUserPoolAuthorizer and authorization scopes are configured to restrict access, the authorization scope is not correctly written to the resulting CloudFormation template. Authenticated Cognito users can then bypass the intended scope restrictions and gain access to protected API resources or methods. The vulnerability requires the RestApi construct, CognitoUserPoolAuthorizer, and authorization scopes to all be present in the application. Patching is available in version 2.148.1 and later.
Affected products
- AWS CDK >=2.142.0, <=2.148.0
Timeline
- 2024-08-27: disclosed
- 2024-08-27: patched: Patch released in CDK 2.148.1