A Trailing Slash Bypassed AWS API Gateway Authorization
📝
内容提要
A security researcher found that adding a trailing slash to AWS HTTP API paths bypassed Lambda authorizer authentication entirely, enabling unauthenticated wire transfers at a fintech. The root...
➡️