Hacking-the-Cloud / hackingthe.cloud

An encyclopedia for offensive and defensive security knowledge in cloud native technologies.
https://hackingthe.cloud
Other
1.73k stars 216 forks source link

Add Cognito user-enumeration bug #302

Closed Frichetten closed 10 months ago

Frichetten commented 11 months ago

As described here, Cognito has a configuration to prevent user-enumeration during login. However, they forgot to apply this to user sign-up as well. Need to validate that this is still the case and add to Hacking the Cloud.