aws-samples / aws-appsync-iot-core-realtime-dashboard

This sample application demonstrates a React based web dashboard receiving real-time updates from IoT sensors. The solution is built with AWS AppSync, AWS Amplify, Amazon Location Service, and AWS IoT Core technologies.
MIT No Attribution
112 stars 31 forks source link

Risk: over-authorization of AWS IoT policy #16

Closed P-Verifier closed 1 year ago

P-Verifier commented 2 years ago

We are a security research team and we recently discovered that there is an over-authorization security issue with this project's IoT policy. The affected file is as following:

1. aws-appsync-iot-core-realtime-dashboard/sensor/policy.json