Tag: access-control

AWS credentials logged

Logging unencrypted AWS credentials can expose them to an attacker.

Unauthenticated Amazon SNS unsubscribe requests might succeed

Failing to set the AuthenticateOnUnsubscribe flag to True when confirming an SNS subscription can lead to unauthenticated cancellations.

Loose file permissions

Weak file permissions can lead to privilege escalation.

Improper certificate validation

Lack of validation of a security certificate can lead to host impersonation and sensitive data leaks.

Improper restriction of rendered UI layers or frames

The application incorrectly restricts frame objects or UI layers that belong to another application or domain.

Session fixation

Session fixation might allow an attacker to steal authenticated session IDs.