ImportantSecurity & Privacy
I bypassed AWS API Gateway auth with a trailing slash. Got $12K bounty
A critical authentication bypass vulnerability in AWS API Gateway was discovered through a simple trailing slash manipulation, demonstrating that fundamental API security controls remain vulnerable to trivial evasion techniques. This $12K bounty finding highlights a systemic risk for IT organizations relying on API Gateway for access control, where configuration oversights can completely bypass authentication mechanisms. CIOs should immediately audit API Gateway deployments for similar misconfigurations and implement stricter validation rules, as this vulnerability type suggests widespread exposure across cloud-dependent enterprises.
Hacker News3 min read
%20(1).png)