CVE-2024-52311: Amazon Data.all

Medium severity, CVSS 6.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired.

Affected products

  • Amazon Data.all: from 1.0.0, before 2.6.1 (fixed in 2.6.1)

Published 2024-11-09. Last modified 2026-06-17.