Trailing slash bypasses AWS API Gateway authorization
A security researcher showed that adding a trailing slash to paths in AWS HTTP APIs completely bypassed Lambda authorizer authentication, allowing unauthenticated access.
Topic cluster
1 source grouped by AFBytes in Tech
AFBytes briefing
Authentication bypasses in widely used cloud services can expose data of U.S. businesses and government agencies that rely on AWS infrastructure.
A security researcher showed that adding a trailing slash to paths in AWS HTTP APIs completely bypassed Lambda authorizer authentication, allowing unauthenticated access.