April 3, 2023, midnight |

The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org

The API action ListObservabilityConfigurationsForAccount did not properly validate the
"AccountId" parameter that was passed to it. As a result, any account ID could be provided
and the API would return the information for that account. This would leak minor information
about the observability configuration for App Runner in the account.

account action api app configuration info information leak observability parameter result return

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)