Amazon AWS Amplify CLI before 12.10.1 incorrectly configured IAM role trust policies for roles associated with Amplify projects. Specifically, when the Authentication component was removed from an Amplify project, the trust policy could retain an "Effect":"Allow" statement for the federated principal cognito-identity.amazonaws.com while removing the protective Condition block that should restrict sts:AssumeRoleWithWebIdentity to an intended Cognito identity pool audience. As a result, roles that should only have been assumable under constrained Cognito conditions could become broadly assumable via web identity federation. The issue affected projects where an authorized AWS user removed the Authentication component from an Amplify project built between August 2019 and January 2024. Supporting reporting indicates the vulnerable trust relationship lacked the required cognito-identity.amazonaws.com:aud restriction and in some cases only constrained cognito-identity.amazonaws.com:amr, which was insufficient. This exposed affected authRole or unauthRole IAM roles to unauthorized assumption using Cognito-issued tokens and STS AssumeRoleWithWebIdentity.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An AWS Amplify-related vulnerability caused certain IAM role trust policies tied to Cognito identity pools to be misconfigured, enabling unauthorized assumption of vulnerable roles. AWS blocked cross-account exploitation and fixed creation of new vulnerable roles, but same-account abuse may still be possible where legacy vulnerable roles and additional Cognito misconfigurations remain.
A vulnerability in AWS Amplify that caused Cognito IAM roles associated with Amplify projects to become publicly assumable, enabling unauthorized cross-account role assumption and access to the permissions attached to those roles. The article describes two variants affecting Amplify-created roles across different time periods.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.