AWS VDP - HackerOne Reports
View on HackerOne33
Total Reports
1
Critical
5
High
23
Medium
1
Low
Non-Production API Endpoints for the cloudwatch Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
Reported by:
nick_frichette_dd
|
Disclosed:
Medium
Weakness: Insufficient Logging
A potential risk in the cloudFrontExtensionsConsole which can be used to privilege escalation.
Reported by:
zolaer9527
|
Disclosed:
Medium
Weakness: Improper Access Control - Generic
Non-Production API Endpoints for the ssm Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
Reported by:
nick_frichette_dd
|
Disclosed:
Medium
Weakness: Insufficient Logging
Bedrock Guardrails Evasion with Prompt Formatting
Reported by:
nkirk-nrlabs
|
Disclosed:
Amazon Kendra Intelligent Ranking Service Reporting "AWS Internal" for CloudTrail Events Generated from FIPS Endpoints
Reported by:
nick_frichette_dd
|
Disclosed:
Medium
Weakness: Insufficient Logging
Non-Production API Endpoints for the Glue Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
Reported by:
nick_frichette_dd
|
Disclosed:
Medium
Weakness: Insufficient Logging
Non-Production API Endpoints for the bedrock Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
Reported by:
nick_frichette_dd
|
Disclosed:
Medium
Weakness: Insufficient Logging
Sensitive API Key Leakage
Reported by:
hemant1
|
Disclosed:
Medium
Weakness: Cleartext Storage of Sensitive Information
Non-Production API Endpoints for the Health Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
Reported by:
nick_frichette_dd
|
Disclosed:
Medium
Weakness: Insufficient Logging
Non-Production API Endpoints for the Forecast Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
Reported by:
nick_frichette_dd
|
Disclosed:
Medium
Weakness: Insufficient Logging
Non-Production API Endpoints for the DocumentDB Elastic Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
Reported by:
nick_frichette_dd
|
Disclosed:
Medium
Weakness: Insufficient Logging
Non-Production API Endpoints for the Route 53 Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
Reported by:
nick_frichette_dd
|
Disclosed:
Medium
Weakness: Insufficient Logging
Amazon Pinpoint SMS and Voice, version 2 Service Reporting "AWS Internal" for CloudTrail Events Generated from FIPS Endpoints
Reported by:
nick_frichette_dd
|
Disclosed:
Medium
Weakness: Insufficient Logging
Previous
Page 2 of 2