wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
306 stars 61 forks source link

Adding AWS Amplify api leaked account ID #150

Closed Frichetten closed 1 year ago

Frichetten commented 1 year ago

I reported an undocumented, "internalonly" API for amplify:GetDistributionDetails, which would take in an Amplify App ID or a CloudFront domain and return the AWS account ID associated with it. I reported it to AWS who disabled the API. Details here