Aug. 19, 2022, midnight |

The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org

Amazon SNS' signature validation in the official SDK relied on a weak regex for default AWS certificate locations,
that would incorrectly match an S3 bucket named `sns`. This bucket happened to be publicly readable and writeable,
allowing an attacker to forge messages to any user of the official SDK SNS validator.

amazon amazon sns attacker aws certificate default forge messages official regex s3 bucket sdk signature sns validation

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC