A Trailing Slash Bypassed AWS API Gateway Authorization

📝

内容提要

A security researcher found that adding a trailing slash to AWS HTTP API paths bypassed Lambda authorizer authentication entirely, enabling unauthenticated wire transfers at a fintech. The root...

🏷️

标签

➡️

继续阅读