low

App Runner cross-tenant observability config info leak

Published Mon, Apr 3rd, 2023
Platforms

Summary

The API action ListObservabilityConfigurationsForAccount did not properly validate the "AccountId" parameter that was passed to it. As a result, any account ID could be provided and the API would return the information for that account. This would leak minor information about the observability configuration for App Runner in the account.

Affected Services

App Runner

Remediation

None required

Tracked CVEs

No tracked CVEs

References

Disclosure Date
Tue, Feb 28th, 2023
Exploitablity Period
Until 2023/03/13
Known ITW Exploitation
-
Detection Methods
-
Piercing Index Rating
-
Discovered by
Nick Frichette