Datadog Security Labs disclosed CVE-2024-28056, an AWS Amplify flaw that left Cognito-linked IAM roles vulnerable to takeover when trust policies omitted the required Cognito identity pool audience restriction. The issue affected two Amplify variants: older CLI-created projects with insecure default trust policies and projects where the authentication component was later removed, leaving overly permissive roles behind. Researchers identified more than 8,000 public IAM role ARNs with recognizable Amplify naming patterns such as authRole and unauthRole, and showed that attackers could use Cognito Basic authflow together with STS to obtain short-lived credentials through
AssumeRoleWithWebIdentity
without additional authorization.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
On 2024-11-21, Hacking the Cloud published a write-up showing that same-account exploitation may still be possible for legacy vulnerable roles if the victim account has a Cognito identity pool with Basic authflow enabled. The article described both unauthenticated and authenticated attack paths and recommended deleting or correcting vulnerable roles rather than relying only on AWS mitigations.
On 2024-04-15, Datadog published details of the two AWS Amplify vulnerability variants, describing how attackers could use Cognito Basic authflow and STS to obtain temporary credentials for vulnerable roles. The company said it had found more than 8,000 public IAM role ARNs during internet-scale testing and had notified affected customers.
In April 2024, AWS updated STS to prevent cross-account assumption of affected roles via AssumeRoleWithWebIdentity. Datadog noted this blocked cross-account abuse, though same-account exploitation could still remain for legacy roles under certain conditions.
In February 2024, AWS hardened IAM so customers could no longer create the affected malformed trust policies lacking the required Cognito audience restriction. This mitigation reduced future exposure from newly created roles.
In January 2024, AWS fixed Amplify CLI and Amplify Studio issues that created or preserved vulnerable IAM trust policies. These changes addressed the application-layer causes of both disclosed variants.
In January 2024, Datadog Security Research identified two AWS Amplify vulnerability variants that could let attackers assume vulnerable Cognito-associated IAM roles using AssumeRoleWithWebIdentity. The flaws stemmed from missing Cognito identity pool audience restrictions in trust policies.
Between August 2019 and January 2024, Amplify CLI and Amplify Studio could leave behind IAM roles with improperly restricted trust policies when the authentication component was removed from a project. Datadog later identified this as the first vulnerability variant.
From July 2018 to August 2019, AWS Amplify CLI created projects with IAM role trust policies that lacked the required Cognito identity pool audience restriction. This later became Datadog's second vulnerability variant affecting Cognito-associated roles.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
hackingthe.cloud
Open sourcesecuritylabs.datadoghq.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.