CVE-2024-52311
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedAuthentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · moderate confidenceIn data.all, Cognito-issued authentication tokens remain valid after user logout because the application does not implement token revocation. This allows any party possessing the token (including malicious actors on shared devices) to continue making authorized API requests until the token naturally expires.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.
NVD · CPE data>= 1.0.0, < 2.6.1CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- Low
- Integrity
- Low
- Availability
- Low
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Verify the installed data.all versionCheck your deployed data.all version by examining the deployed artifacts, Docker image tags, Helm chart version, or the version file in the application root. Compare against the vulnerable range: >= 1.0.0 and < 2.6.1.Affected if The installed version falls within >= 1.0.0 and < 2.6.1.
-
Locate the logout implementationSearch the codebase for the logout handler or session termination function, typically found in authentication or user management modules. Look for keywords like 'logout', 'signout', 'session terminate', or the API endpoint handling user sign-out requests.Affected if A logout endpoint or function exists but does not invalidate the Cognito-issued access or refresh tokens.
-
Inspect token invalidation logicExamine the logout implementation code to determine whether it calls Cognito's token revocation endpoint (https://cognito-idp.<region>.amazonaws.com/oauth2/revoke) or implements a server-side token blacklist. Look for HTTP POST requests to Cognito's revocation endpoint or database checks against a blacklist table.Affected if The logout logic removes tokens only on the client side (clearing local storage/cookies) without notifying Cognito or maintaining a server-side invalidation list.
-
Verify token validation during API requestsReview the API gateway or authentication middleware that validates incoming requests. Determine whether it checks only the token signature/expiry or also consults a revocation list or Cognito's user pool for token status.Affected if The validation logic accepts tokens based solely on cryptographic validity and expiration without checking if the token has been explicitly revoked.
-
Check for refresh token revocation on logoutIf a refresh token flow exists, verify whether the logout process attempts to revoke the refresh token via Cognito's revocation endpoint. This is critical because refresh tokens can obtain new access tokens even after logout.Affected if Refresh tokens remain usable after logout because they are not revoked through Cognito's token revocation mechanism.
You are affected if your data.all version is between 1.0.0 and 2.6.1 and the logout flow does not invoke Cognito's token revocation endpoint or maintain a server-side token blacklist.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scoped2.6.1
Implement token invalidation on logout using Cognito's token revocation endpoint or server-side token blacklist to ensure issued tokens are immediately invalidated rather than relying solely on client-side token removal.
2.6.1 or later
- Upgrade data.all to version 2.6.1 or later to receive the token invalidation fix
- After upgrade, verify that logout functionality properly invalidates Cognito authentication tokens
- Confirm that previously issued tokens can no longer be used after user logout
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation4.0 h
- Implementation12.0 h
- Testing6.0 h
- Review / QA3.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $7,040.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2024-52311 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2024-52311 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data