天下漏洞,尽知其名
MEDIUM

CVE-2026-108096 AWS Amplify 授权不当漏洞

影响已认证用户可越权读取其他用户的数据记录

AI 研判

AWS Amplify API Category 中由 @aws-amplify/graphql-index-transformer 生成的查询解析器存在授权不当问题。在 3.1.2 之前的版本中,已认证的远程用户可通过构造查询读取同一应用中其他用户拥有的记录。该漏洞 CVSS 评分为 6.5,属于中危。

影响范围

AWS Amplify

@aws-amplify/graphql-index-transformer 3.1.2 之前的版本;修复版本包含在 @aws-amplify/data-construct 1.17.4 和 @aws-amplify/graphql-api-construct 1.21.4 中。

漏洞详情

漏洞类型为授权不当(越权访问)。成因是 graphql-index-transformer 生成的查询解析器未正确校验记录归属,导致已认证用户可绕过所有权限制。攻击者通过构造特定 GraphQL 查询即可读取其他用户的数据。

利用条件与风险

利用前提是攻击者拥有该应用的有效认证身份,实战中可导致同应用内用户数据横向泄露,风险中等。

修复建议

升级 @aws-amplify/graphql-index-transformer 至 3.1.2 或更高版本(对应 data-construct 1.17.4、graphql-api-construct 1.21.4),并重新部署后端;如有 fork 或衍生代码需同步修补。暂无其他公开缓解措施。

原始情报

Improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer in AWS Amplify API Category before 3.1.2 might allow an authenticated remote user to read records owned by other users of the same application via crafted queries.

This issue has been addressed in @aws-amplify/graphql-index-transformer 3.1.2 https://www.npmjs.com/package/@aws-amplify/graphql-index-transformer/v/3.1.2 (included in @aws-amplify/data-construct 1.17.4 https://www.npmjs.com/package/@aws-amplify/data-construct/v/1.17.4 and @aws-amplify/graphql-api-construct 1.21.4 https://www.npmjs.com/package/@aws-amplify/graphql-api-construct/v/1.21.4 ). We recommend upgrading to the latest version ensuring any forked or derivative code is patched to incorporate the new fixes and then redeploying their backend.