Cognito issues JWT ID and access tokens whose claims (groups, custom: attributes, scopes) applications and identity pools consume for authorization. Where an app trusts a claim the user can influence, or validates tokens weakly, manipulating claims elevates the session.
Where claims are trusted#
- Identity-pool role mapping: a pool can map users to roles by a token claim (a group or attribute), so controlling that claim selects a more privileged role at
get-credentials-for-identity. - App-side authorization: an app that reads
cognito:groupsor acustom:claim and trusts it grants whatever the claim says.
# decode a held token to see the claims in play
echo "<jwt>" | cut -d. -f2 | base64 -d 2>/dev/null
Exploitation notes#
- Group membership drives
cognito:groups; if you can join a group (admin-set or self-service), the next token carries it. - Role-mapping rules that key on a writable attribute combine directly with user pool attribute abuse.
- Weak signature or audience validation on the app side lets a crafted token through; test whether the app verifies the Cognito JWKS and
aud.
Tools#
- jwt_tool: inspect and test the token's claims and validation.
- AWS CLI (
cognito-identity get-credentials-for-identity) to turn a mapped token into role credentials.