Hacking-the-Cloud / hackingthe.cloud

An encyclopedia for offensive and defensive security knowledge in cloud native technologies.

Home Page:https://hackingthe.cloud

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Add Cognito user-enumeration bug

Frichetten opened this issue · comments

As described here, Cognito has a configuration to prevent user-enumeration during login. However, they forgot to apply this to user sign-up as well. Need to validate that this is still the case and add to Hacking the Cloud.