mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-04 02:04:06 +00:00
chore(aws): enhance metadata for cognito service (#8853)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
This commit is contained in:
co-authored by
Daniel Barranquero
parent
270266c906
commit
864b2099c3
@@ -85,7 +85,7 @@ jobs:
|
||||
|
||||
- name: Check format with black
|
||||
if: steps.check-changes.outputs.any_changed == 'true'
|
||||
run: poetry run black --exclude api ui skills --check .
|
||||
run: poetry run black --exclude "api|ui|skills" --check .
|
||||
|
||||
- name: Lint with pylint
|
||||
if: steps.check-changes.outputs.any_changed == 'true'
|
||||
|
||||
@@ -48,6 +48,7 @@ All notable changes to the **Prowler SDK** are documented in this file.
|
||||
- Update AWS RDS service metadata to new format [(#9551)](https://github.com/prowler-cloud/prowler/pull/9551)
|
||||
- Update AWS Bedrock service metadata to new format [(#8827)](https://github.com/prowler-cloud/prowler/pull/8827)
|
||||
- Update AWS IAM service metadata to new format [(#9550)](https://github.com/prowler-cloud/prowler/pull/9550)
|
||||
- Update AWS Cognito service metadata to new format [(#8853)](https://github.com/prowler-cloud/prowler/pull/8853)
|
||||
|
||||
---
|
||||
|
||||
|
||||
+22
-13
@@ -1,30 +1,39 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_identity_pool_guest_access_disabled",
|
||||
"CheckTitle": "Ensure Cognito Identity Pool has guest access disabled",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Cognito identity pool has guest access disabled",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"TTPs/Initial Access"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:identitypool/identitypool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "Guest access allows unauthenticated users to access your identity pool. This is useful for public websites that allow users to sign in with a social identity provider, but it can also be a security risk. If you don't need guest access, you should disable it.",
|
||||
"Risk": "If guest access is enabled, unauthenticated users can access your identity pool. This can be a security risk if you don't need guest access.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/location/latest/developerguide/authenticating-using-cognito.html",
|
||||
"Description": "**Amazon Cognito identity pools** are evaluated for **guest access** to unauthenticated identities. The assessment considers the `allow_unauthenticated_identities` setting and whether an unauthenticated role can be assumed by guests.",
|
||||
"Risk": "With **guest access**, unauthenticated users receive temporary credentials, reducing **confidentiality** and **integrity** controls. Overly permissive unauthenticated roles enable data reads/writes, API abuse, and resource consumption, risking **data exposure**, unauthorized changes, and **cost amplification**.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://docs.aws.amazon.com/location/latest/developerguide/authenticating-using-cognito.html",
|
||||
"https://support.icompaas.com/support/solutions/articles/62000233674-ensure-cognito-identity-pool-has-guest-access-disabled"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"CLI": "aws cognito-identity update-identity-pool --identity-pool-id <example_resource_id> --identity-pool-name <example_resource_name> --no-allow-unauthenticated-identities",
|
||||
"NativeIaC": "```yaml\n# CloudFormation: Disable guest (unauthenticated) access in an Identity Pool\nResources:\n <example_resource_name>:\n Type: AWS::Cognito::IdentityPool\n Properties:\n AllowUnauthenticatedIdentities: false # Critical: disables unauthenticated (guest) identities\n```",
|
||||
"Other": "1. Open the Amazon Cognito console and go to Identity pools\n2. Select the identity pool <example_resource_name>\n3. Click Edit (or Settings) for Authentication settings\n4. Turn off/clear \"Enable access to unauthenticated identities\"\n5. Save changes",
|
||||
"Terraform": "```hcl\n# Disable guest (unauthenticated) access in an Identity Pool\nresource \"aws_cognito_identity_pool\" \"<example_resource_name>\" {\n identity_pool_name = \"<example_resource_name>\"\n allow_unauthenticated_identities = false # Critical: disables guest access\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Gues access should be disabled for Cognito Identity Pool. To disable guest access, follow the steps in the Amazon Cognito documentation.",
|
||||
"Url": "https://docs.aws.amazon.com/location/latest/developerguide/authenticating-using-cognito.html"
|
||||
"Text": "Disable guest access by setting `allow_unauthenticated_identities` to `false` unless strictly required.\n\nIf needed:\n- Enforce **least privilege** with tight resource scopes and conditions\n- Shorten session lifetimes and rate-limit usage\n- Prefer authenticated flows (user pools or federated IdPs)\n- Monitor access for **defense in depth**",
|
||||
"Url": "https://hub.prowler.com/check/cognito_identity_pool_guest_access_disabled"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"identity-access"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+24
-14
@@ -1,30 +1,40 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_advanced_security_enabled",
|
||||
"CheckTitle": "Ensure cognito user pools has advanced security enabled with full-function",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Cognito user pool has advanced security enforced with full-function mode",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "Advanced security features for Amazon Cognito User Pools provide additional security for your user pool. These features include compromised credentials protection, phone number verification, and account takeover protection.",
|
||||
"Risk": "If advanced security features are not enabled, your user pool is more vulnerable to unauthorized access.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pool-settings-advanced-security.html",
|
||||
"Description": "**Amazon Cognito user pools** are evaluated for **Threat protection (advanced security)** mode: `ENFORCED` (full-function) vs `AUDIT` or disabled. This indicates whether adaptive risk responses and compromised-credential checks are applied during authentication.",
|
||||
"Risk": "Without enforced threat protection, risky sign-ins aren't blocked-only logged-enabling credential stuffing, brute force, and account takeover. This threatens confidentiality and integrity via unauthorized access and token misuse, and can degrade availability through automated abuse.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pool-settings-advanced-security.html",
|
||||
"https://support.icompaas.com/support/solutions/articles/62000233667-ensure-cognito-user-pools-has-advanced-security-enabled-with-full-function"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"CLI": "aws cognito-idp update-user-pool --user-pool-id <example_resource_id> --user-pool-add-ons AdvancedSecurityMode=ENFORCED",
|
||||
"NativeIaC": "```yaml\nResources:\n <example_resource_name>:\n Type: AWS::Cognito::UserPool\n Properties:\n # Critical: Enables full-function threat protection (advanced security)\n UserPoolAddOns:\n AdvancedSecurityMode: ENFORCED # Sets advanced security to ENFORCED\n```",
|
||||
"Other": "1. In the AWS Console, go to Cognito > User pools and select your pool\n2. Open Threat protection\n3. Click Activate (enable Plus feature plan if prompted)\n4. Set Enforcement mode to Full function (ENFORCED)\n5. Click Save changes",
|
||||
"Terraform": "```hcl\nresource \"aws_cognito_user_pool\" \"<example_resource_name>\" {\n name = \"<example_resource_name>\"\n\n # Critical: Enables full-function threat protection (advanced security)\n user_pool_add_ons {\n advanced_security_mode = \"ENFORCED\" # Set to ENFORCED to pass the check\n }\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "To enable advanced security features for an Amazon Cognito User Pool, follow the instructions in the Amazon Cognito documentation.",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pool-settings-advanced-security.html"
|
||||
"Text": "Set Threat protection to `ENFORCED` to apply automatic mitigations.\n- Require step-up **MFA** on risky events\n- Block compromised credentials\n- Use IP allow/deny lists and export logs for monitoring\n*Baseline in* `AUDIT`, then enforce. Apply **defense in depth** and **least privilege** across apps and clients.",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_advanced_security_enabled"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"identity-access",
|
||||
"threat-detection"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+24
-13
@@ -1,30 +1,41 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_blocks_compromised_credentials_sign_in_attempts",
|
||||
"CheckTitle": "Ensure that advanced security features are enabled for Amazon Cognito User Pools to block sign-in by users with suspected compromised credentials",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Cognito user pool blocks sign-in attempts with suspected compromised credentials",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices/Runtime Behavior Analysis",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices",
|
||||
"TTPs/Initial Access"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "Amazon Cognito User Pools can be configured to block sign-in by users with suspected compromised credentials. This feature uses Amazon Cognito advanced security features to detect anomalous sign-in attempts and block them. When enabled, Amazon Cognito User Pools will block sign-in by users with suspected compromised credentials. This helps protect your users from unauthorized access to their accounts.",
|
||||
"Risk": "If advanced security features are not enabled for an Amazon Cognito User Pool, users with compromised credentials may be able to sign in to their accounts. This could lead to unauthorized access to user data and other resources.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pool-settings-advanced-security.html",
|
||||
"Description": "Amazon Cognito user pool threat protection **blocks sign-ins** when **compromised credentials** are detected. Advanced security is `ENFORCED`, and the compromised-credentials policy applies a `BLOCK` action to sign-in events.",
|
||||
"Risk": "Allowing sign-in with leaked or reused passwords enables **account takeover**, exposing tokens and profile data (**confidentiality**), permitting unauthorized changes (**integrity**), and enabling abuse of linked APIs and sessions (**availability** impacts via misuse or lockout).",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pool-settings-advanced-security.html",
|
||||
"https://support.icompaas.com/support/solutions/articles/62000233676-ensure-that-your-amazon-cognito-user-pool-blocks-potential-malicious-sign-in-attempts"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"NativeIaC": "```yaml\n# Enable threat protection and block compromised credentials on sign-in\nResources:\n UserPool:\n Type: AWS::Cognito::UserPool\n Properties:\n UserPoolName: <example_resource_name>\n UserPoolAddOns:\n AdvancedSecurityMode: ENFORCED # Critical: enables full threat protection required for blocking actions\n\n RiskConfig:\n Type: AWS::Cognito::UserPoolRiskConfigurationAttachment\n Properties:\n UserPoolId: !Ref UserPool\n CompromisedCredentialsRiskConfiguration:\n Actions:\n EventAction: BLOCK # Critical: block sign-in with suspected compromised credentials\n EventFilter:\n - SIGN_IN # Critical: apply the block action to sign-in events\n```",
|
||||
"Other": "1. In the AWS Console, go to Amazon Cognito > User pools and select <example_resource_name>\n2. Open Threat protection and click Activate (if not already active)\n3. Set Enforcement mode to Full function (this sets Advanced security to ENFORCED)\n4. Under Compromised credentials, ensure Event detection includes Sign-in and set Action to Block sign-in\n5. Click Save changes",
|
||||
"Terraform": "```hcl\n# Enable threat protection and block compromised credentials on sign-in\nresource \"aws_cognito_user_pool\" \"example\" {\n name = \"<example_resource_name>\"\n user_pool_add_ons {\n advanced_security_mode = \"ENFORCED\" # Critical: enables full threat protection required for blocking actions\n }\n}\n\nresource \"aws_cognito_risk_configuration\" \"example\" {\n user_pool_id = aws_cognito_user_pool.example.id\n compromised_credentials_risk_configuration {\n actions {\n event_action = \"BLOCK\" # Critical: block sign-in with suspected compromised credentials\n }\n event_filter = [\"SIGN_IN\"] # Critical: apply the block action to sign-in events\n }\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "To enable advanced security features for an Amazon Cognito User Pool, follow the steps below:",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pool-settings-advanced-security.html"
|
||||
"Text": "Enable threat protection with advanced security `ENFORCED` and set compromised-credential responses to `BLOCK` for sign-ins. Combine with **adaptive authentication** and **MFA** for higher assurance, monitor risk logs, and enforce strong password policies to prevent reuse-applying **defense in depth**.",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_blocks_compromised_credentials_sign_in_attempts"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"identity-access",
|
||||
"threat-detection"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+24
-13
@@ -1,30 +1,41 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_blocks_potential_malicious_sign_in_attempts",
|
||||
"CheckTitle": "Ensure that your Amazon Cognito user pool blocks potential malicious sign-in attempts",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Amazon Cognito user pool blocks all potential malicious sign-in attempts",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices",
|
||||
"TTPs/Initial Access"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "Amazon Cognito provides adaptive authentication, which helps protect your applications from malicious actors and compromised credentials by evaluating the risk associated with each user login and providing the appropriate level of security to mitigate that risk. Adaptive authentication is a feature of advanced security that you can enable for your user pool. When adaptive authentication is enabled, Amazon Cognito evaluates the risk associated with each user login and provides the appropriate level of security to mitigate that risk. You can configure adaptive authentication to block sign-in attempts that are likely to be malicious.",
|
||||
"Risk": "If adaptive authentication with automatic risk response as block sign-in is not enabled, your user pool may not be able to block sign-in attempts that are likely to be malicious.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pool-settings-advanced-security.html",
|
||||
"Description": "**Amazon Cognito user pool** with **threat protection** in `ENFORCED` mode and **adaptive authentication** actions set to `BLOCK` for `low`, `medium`, and `high` account-takeover risk levels.\n\nEvaluates the user pool's risk configuration to confirm risky sign-in attempts are blocked across all severities.",
|
||||
"Risk": "Permitting risky sign-ins degrades **confidentiality** and **integrity**. Attackers with **stolen or guessed credentials** can achieve **account takeover**, access data, change credentials, and escalate privileges, enabling lateral movement and persistence.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pool-settings-advanced-security.html",
|
||||
"https://support.icompaas.com/support/solutions/articles/62000233676-ensure-that-your-amazon-cognito-user-pool-blocks-potential-malicious-sign-in-attempts"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"NativeIaC": "```yaml\n# CloudFormation: Enforce threat protection and block all risk levels\nResources:\n UserPool:\n Type: AWS::Cognito::UserPool\n Properties:\n UserPoolAddOns:\n AdvancedSecurityMode: ENFORCED # Critical: Enables Full function threat protection (required for PASS)\n\n RiskConfig:\n Type: AWS::Cognito::UserPoolRiskConfigurationAttachment\n Properties:\n UserPoolId: !Ref UserPool\n AccountTakeoverRiskConfiguration:\n Actions:\n LowAction:\n EventAction: BLOCK # Critical: Block low-risk sign-ins\n Notify: false\n MediumAction:\n EventAction: BLOCK # Critical: Block medium-risk sign-ins\n Notify: false\n HighAction:\n EventAction: BLOCK # Critical: Block high-risk sign-ins\n Notify: false\n```",
|
||||
"Other": "1. In the AWS Console, go to Cognito > User pools and select <example_resource_name>\n2. Open Threat protection\n3. Set Enforcement mode to Full function and Save (enables Advanced security)\n4. In Account takeover risk configuration, set Low, Medium, and High to Block sign-in\n5. Save changes",
|
||||
"Terraform": "```hcl\n# Enforce threat protection and block all risk levels\nresource \"aws_cognito_user_pool\" \"<example_resource_name>\" {\n user_pool_add_ons {\n advanced_security_mode = \"ENFORCED\" # Critical: Enables Full function threat protection (required for PASS)\n }\n}\n\nresource \"aws_cognito_risk_configuration\" \"<example_resource_name>\" {\n user_pool_id = aws_cognito_user_pool.<example_resource_name>.id\n\n account_takeover_risk_configuration {\n actions {\n low_action {\n event_action = \"BLOCK\" # Critical: Block low-risk sign-ins\n notify = false\n }\n medium_action {\n event_action = \"BLOCK\" # Critical: Block medium-risk sign-ins\n notify = false\n }\n high_action {\n event_action = \"BLOCK\" # Critical: Block high-risk sign-ins\n notify = false\n }\n }\n }\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "To enable adaptive authentication with automatic risk response as block sign-in, perform the following actions:",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pool-settings-advanced-security.html"
|
||||
"Text": "Enable **threat protection** in `ENFORCED` mode and configure **adaptive authentication** to `BLOCK` at all risk levels.\n\nApply **least privilege** and **defense in depth**: require MFA, avoid broad Always-allow IPs, and monitor user event logs to tune responses and exceptions.",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_blocks_potential_malicious_sign_in_attempts"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"threat-detection",
|
||||
"identity-access"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+27
-14
@@ -1,30 +1,43 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_client_prevent_user_existence_errors",
|
||||
"CheckTitle": "Amazon Cognito User Pool should prevent user existence errors",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Amazon Cognito user pool client has Prevent User Existence Errors enabled",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices",
|
||||
"TTPs/Discovery",
|
||||
"Effects/Data Exposure"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPoolClient",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "Amazon Cognito User Pool should be configured to prevent user existence errors. This setting prevents user existence errors by requiring the user to enter a username and password to sign in. If the user does not exist, the user will receive an error message.",
|
||||
"Risk": "Revealing user existence errors can be a security risk as it can allow an attacker to determine if a user exists in the system. This can be used to perform user enumeration attacks.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pool-managing-errors.html",
|
||||
"Description": "Amazon Cognito app clients use `PreventUserExistenceErrors` to suppress **user-existence disclosures**, keeping authentication, confirmation, and recovery responses generic rather than indicating whether a username exists.",
|
||||
"Risk": "If responses reveal user existence, adversaries can **enumerate accounts**, enabling targeted **credential stuffing**, **brute force**, and **password-reset abuse**. This facilitates **account takeover**, leaks PII, and can degrade availability through automated lockouts.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://repost.aws/knowledge-center/cognito-prevent-user-existence-errors",
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pool-managing-errors.html",
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-client-apps.html",
|
||||
"https://docs.aws.amazon.com/AWSCloudFormation/latest/TemplateReference/aws-resource-cognito-userpoolclient.html"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"CLI": "aws cognito-idp update-user-pool-client --user-pool-id <USER_POOL_ID> --client-id <APP_CLIENT_ID> --prevent-user-existence-errors ENABLED",
|
||||
"NativeIaC": "```yaml\nResources:\n <example_resource_name>:\n Type: AWS::Cognito::UserPoolClient\n Properties:\n UserPoolId: <example_resource_id>\n PreventUserExistenceErrors: ENABLED # Critical: enables suppression of user existence errors to pass the check\n ClientName: <example_resource_name>\n```",
|
||||
"Other": "1. Open the Amazon Cognito console and go to User pools\n2. Select your user pool, then go to App integration > App clients\n3. Choose the target app client and click Edit\n4. Set Prevent user existence errors to Enabled\n5. Click Save changes",
|
||||
"Terraform": "```hcl\nresource \"aws_cognito_user_pool_client\" \"<example_resource_name>\" {\n name = \"<example_resource_name>\"\n user_pool_id = \"<example_resource_id>\"\n\n prevent_user_existence_errors = \"ENABLED\" # Critical: prevents revealing if a user exists\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "To prevent user existence errors, you should configure the Amazon Cognito User Pool to require a username and password to sign in. If the user does not exist, the user will receive an error message.",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pool-managing-errors.html"
|
||||
"Text": "Enable **user-existence suppression** on all app clients (`PreventUserExistenceErrors=ENABLED`). Apply **least disclosure** with generic messages across all auth flows and aliases. Strengthen with **MFA**, **rate limiting**, and **anomalous login detection** for **defense in depth**.",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_client_prevent_user_existence_errors"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"identity-access"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+24
-14
@@ -1,30 +1,40 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_client_token_revocation_enabled",
|
||||
"CheckTitle": "Ensure that token revocation is enabled for Amazon Cognito User Pools",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Amazon Cognito user pool client has token revocation enabled",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices",
|
||||
"TTPs/Persistence"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPoolClient",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "Token revocation is a security feature that allows you to revoke tokens and end sessions for users. When you enable token revocation, Amazon Cognito automatically revokes tokens for users who sign out or are deleted. This helps protect your users' data and prevent unauthorized access to your resources.",
|
||||
"Risk": "If token revocation is not enabled, users' tokens will not be revoked when they sign out or are deleted. This can lead to unauthorized access to your resources.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito/latest/developerguide/token-revocation.html",
|
||||
"Description": "**Amazon Cognito user pool app clients** are evaluated for **token revocation** being enabled via `EnableTokenRevocation`.\n\nThis identifies whether each client can invalidate refresh tokens and the access/ID tokens derived from them to end user sessions.",
|
||||
"Risk": "Without **token revocation**, stolen or residual refresh tokens remain valid until expiry, enabling continued access after sign-out or account disablement. This undermines **confidentiality** and **integrity** by permitting unauthorized API calls, data exfiltration, and session hijacking.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://repost.aws/knowledge-center/cognito-revoke-refresh-tokens",
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/token-revocation.html"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"CLI": "aws cognito-idp update-user-pool-client --user-pool-id <USER_POOL_ID> --client-id <USER_POOL_CLIENT_ID> --enable-token-revocation",
|
||||
"NativeIaC": "```yaml\nResources:\n <example_resource_name>:\n Type: AWS::Cognito::UserPoolClient\n Properties:\n UserPoolId: \"<example_resource_id>\"\n EnableTokenRevocation: true # Critical: Enables token revocation so the client passes the check\n```",
|
||||
"Other": "1. In the AWS Console, go to Amazon Cognito > User pools\n2. Select your user pool, then open App integration > App clients\n3. Click the target app client and choose Edit\n4. Under Advanced configuration, enable Token revocation\n5. Click Save changes",
|
||||
"Terraform": "```hcl\nresource \"aws_cognito_user_pool_client\" \"<example_resource_name>\" {\n name = \"<example_resource_name>\"\n user_pool_id = \"<example_resource_id>\"\n enable_token_revocation = true # Critical: Enables token revocation so the client passes the check\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "To enable token revocation for an Amazon Cognito User Pool, use the Amazon Cognito console or the AWS CLI. For more information, see the Amazon Cognito documentation.",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/token-revocation.html"
|
||||
"Text": "Enable `EnableTokenRevocation: true` on all app clients.\n\nAlso:\n- Use refresh token rotation\n- Shorten token lifetimes\n- Apply least privilege to scopes\n- Enforce user/admin sign-out to terminate sessions\n- Monitor for anomalous token reuse",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_client_token_revocation_enabled"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"identity-access"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+25
-14
@@ -1,30 +1,41 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_deletion_protection_enabled",
|
||||
"CheckTitle": "Ensure cognito user pools deletion protection enabled to prevent accidental deletion",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Cognito user pool has deletion protection enabled",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices",
|
||||
"Effects/Data Destruction"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "Deletion protection is a feature that allows you to lock a user pool to prevent it from being deleted. When deletion protection is enabled, you cannot delete the user pool. By default, deletion protection is disabled",
|
||||
"Risk": "If deletion protection is not enabled, the user pool can be deleted by any user with the necessary permissions. This can lead to loss of data and service disruption",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-deletion-protection.html",
|
||||
"Description": "**Amazon Cognito user pools** have **deletion protection** set to `ACTIVE`. The evaluation inspects each user pool's deletion protection status.",
|
||||
"Risk": "Without **deletion protection**, any principal with delete rights can remove a user pool in one action, causing immediate **authentication outages**. Identities and configurations are lost, breaking sign-ins and tokens, harming **availability** and **integrity**, and prolonging recovery if exports/backups are stale.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-deletion-protection.html",
|
||||
"https://repost.aws/questions/QUDX0aXegdThit0uD5kB_Fjw/cognito-user-pool-cannot-be-deleted-from-aws-console",
|
||||
"https://support.icompaas.com/support/solutions/articles/62000233677-ensure-cognito-user-pools-deletion-protection-enabled-to-prevent-accidental-deletion"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"CLI": "aws cognito-idp update-user-pool --user-pool-id <example_resource_id> --deletion-protection ACTIVE",
|
||||
"NativeIaC": "```yaml\nResources:\n <example_resource_name>:\n Type: AWS::Cognito::UserPool\n Properties:\n DeletionProtection: ACTIVE # Critical: Enables deletion protection to prevent accidental pool deletion\n```",
|
||||
"Other": "1. Open the AWS Management Console and go to Amazon Cognito\n2. Click User pools and select your pool\n3. Go to Settings > Deletion protection\n4. Click Activate (or toggle On) and Save",
|
||||
"Terraform": "```hcl\nresource \"aws_cognito_user_pool\" \"<example_resource_name>\" {\n name = \"<example_resource_name>\"\n deletion_protection = \"ACTIVE\" # Critical: Enables deletion protection to prevent accidental pool deletion\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Deletion protection should be enabled for the user pool to prevent accidental deletion",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-deletion-protection.html"
|
||||
"Text": "Enable **deletion protection** (`ACTIVE`) on all production user pools.\n- Enforce **least privilege** by restricting delete permissions\n- Require **change control** and multi-party approval to deactivate protection\n- Add **monitoring and alerts** for status changes as **defense in depth**",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_deletion_protection_enabled"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"resilience"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+23
-14
@@ -1,30 +1,39 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_mfa_enabled",
|
||||
"CheckTitle": "Ensure Multi-Factor Authentication (MFA) is enabled for Amazon Cognito User Pools",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Amazon Cognito user pool requires Multi-Factor Authentication (MFA)",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices",
|
||||
"TTPs/Initial Access/Unauthorized Access"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "Checks whether Multi-Factor Authentication (MFA) is enabled for Amazon Cognito User Pools.",
|
||||
"Risk": "If MFA is not enabled, unauthorized users could gain access to the user pool and potentially compromise the security of the application.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-mfa.html",
|
||||
"Description": "**Amazon Cognito user pools** with **MFA** set to `ON`, indicating an additional factor is enforced during authentication",
|
||||
"Risk": "Without **MFA**, password-only sign-in increases **account takeover** via phishing, brute force, and credential stuffing. Compromised accounts yield valid tokens to access data and APIs, alter configurations, and move laterally, eroding **confidentiality** and **integrity**, and potentially affecting **availability** through abuse.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-mfa.html"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"CLI": "aws cognito-idp set-user-pool-mfa-config --user-pool-id <example_resource_id> --software-token-mfa-configuration Enabled=true --mfa-configuration ON",
|
||||
"NativeIaC": "```yaml\n# CloudFormation: Require MFA and enable TOTP\nResources:\n <example_resource_name>:\n Type: AWS::Cognito::UserPool\n Properties:\n MfaConfiguration: ON # Critical: sets MFA to required\n SoftwareTokenMfaConfiguration:\n Enabled: true # Critical: enables TOTP so ON is valid\n```",
|
||||
"Other": "1. In AWS Console, go to Amazon Cognito > User pools\n2. Select your user pool\n3. Open Sign-in > Multi-factor authentication > Edit\n4. Set MFA enforcement to Require MFA\n5. Enable Authenticator app (TOTP) under MFA methods\n6. Click Save changes",
|
||||
"Terraform": "```hcl\n# Terraform: Require MFA and enable TOTP\nresource \"aws_cognito_user_pool\" \"<example_resource_name>\" {\n name = \"<example_resource_name>\"\n mfa_configuration = \"ON\" # Critical: sets MFA to required\n\n software_token_mfa_configuration {\n enabled = true # Critical: enables TOTP so ON is valid\n }\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "To enable MFA for an Amazon Cognito User Pool, follow the instructions in the Amazon Cognito documentation.",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-mfa.html"
|
||||
"Text": "Enable **MFA** at the user pool level (`Required` or risk-based) as a **defense-in-depth** control. Prefer **TOTP** or phishing-resistant methods over SMS. Require factor enrollment during onboarding, and enforce **least privilege** on downstream permissions. Complement with anomaly detection and session hardening to prevent and contain ATO.",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_mfa_enabled"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"identity-access"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+24
-14
@@ -1,30 +1,40 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_password_policy_lowercase",
|
||||
"CheckTitle": "Ensure Cognito User Pool has password policy to require at least one lowercase letter",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Cognito user pool password policy requires at least one lowercase letter",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices",
|
||||
"TTPs/Initial Access"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "User pool password policy should require at least one lowercase letter.",
|
||||
"Risk": "If the password policy does not require at least one lowercase letter, it may be easier for an attacker to crack the password.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html",
|
||||
"Description": "**Amazon Cognito user pools** are assessed for a password policy that includes a **lowercase character requirement**. Pools with `require_lowercase` set are distinguished from those without a policy, which inherently lack this requirement.",
|
||||
"Risk": "Absent a **lowercase requirement** reduces password complexity and the overall **keyspace**, making **brute-force** and credential stuffing more feasible. Successful guessing enables account takeover, exposing user data and tokens and permitting profile changes, harming **confidentiality** and **integrity**.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/managing-users-passwords.html",
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"CLI": "aws cognito-idp update-user-pool --user-pool-id <example_resource_id> --policies \"PasswordPolicy={RequireLowercase=true}\"",
|
||||
"NativeIaC": "```yaml\nResources:\n UserPool:\n Type: AWS::Cognito::UserPool\n Properties:\n Policies:\n PasswordPolicy:\n RequireLowercase: true # Critical: requires at least one lowercase letter in passwords\n```",
|
||||
"Other": "1. Open the Amazon Cognito console and go to User pools\n2. Select your user pool\n3. Navigate to Authentication (or Authentication methods) > Password policy\n4. Enable Require lowercase (Lowercase letters)\n5. Click Save changes",
|
||||
"Terraform": "```hcl\nresource \"aws_cognito_user_pool\" \"pool\" {\n name = \"<example_resource_name>\"\n\n password_policy {\n require_lowercase = true # Critical: enforces at least one lowercase character\n }\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "To require at least one lowercase letter in the password, update the password policy for the user pool.",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html"
|
||||
"Text": "Enforce a strong password policy with `require_lowercase: true`, adequate length, and mixed character types. Complement with **defense in depth**: enable **MFA**, apply rate limiting or lockout for failed attempts, and block common passwords. Review regularly to match business risk and user population.",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_password_policy_lowercase"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"identity-access"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+24
-14
@@ -1,30 +1,40 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_password_policy_minimum_length_14",
|
||||
"CheckTitle": "Ensure that the password policy for your user pools require a minimum length of 14 or greater",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Cognito user pool has a password policy with a minimum length of 14 characters or more",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"TTPs/Initial Access",
|
||||
"TTPs/Credential Access"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "User pools allow you to configure a password policy for your user pool to specify complexity requirements for user passwords. The password policy for your user pools should require a minimum length of 14 or greater.",
|
||||
"Risk": "If the password policy for your user pools does not require a minimum length of 14 or greater, it may be easier for attackers to guess or brute force user passwords.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html",
|
||||
"Description": "**Amazon Cognito user pools** should have a **password policy** requiring a **minimum length** of `14`.\n\nThis evaluation detects pools without a policy or with `minimum_length` below `14`.",
|
||||
"Risk": "Low or missing password minimums enable weak credentials, increasing successful **brute force**, **password spraying**, and **credential stuffing** against sign-in endpoints.\n\nResulting **account takeover** threatens confidentiality (data exposure) and integrity/availability (unauthorized changes and abuse).",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html",
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/managing-users-passwords.html"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"CLI": "aws cognito-idp update-user-pool --user-pool-id <example_resource_id> --policies \"PasswordPolicy={MinimumLength=14}\"",
|
||||
"NativeIaC": "```yaml\nResources:\n <example_resource_name>:\n Type: AWS::Cognito::UserPool\n Properties:\n Policies:\n PasswordPolicy:\n MinimumLength: 14 # Critical: sets minimum password length to >=14 to pass the check\n```",
|
||||
"Other": "1. Open the Amazon Cognito console and go to User pools\n2. Select your user pool\n3. Go to Authentication (or Authentication methods) > Password policy\n4. Set Minimum password length to 14\n5. Click Save changes",
|
||||
"Terraform": "```hcl\nresource \"aws_cognito_user_pool\" \"<example_resource_name>\" {\n name = \"<example_resource_name>\"\n\n password_policy {\n minimum_length = 14 # Critical: enforce min length >=14 to pass the check\n }\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "To require a minimum length of 14 or greater for user passwords in your user pools, you can update the password policy for your user pool using the AWS Management Console, AWS CLI, or SDK.",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html"
|
||||
"Text": "Adopt a strong **password policy** with `minimum_length` `14`, favoring long passphrases.\n- Require mixed character types and block common passwords\n- Enforce password history where appropriate\n- Pair with **MFA** and adaptive risk controls for defense in depth",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_password_policy_minimum_length_14"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"identity-access"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+26
-14
@@ -1,30 +1,42 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_password_policy_number",
|
||||
"CheckTitle": "Ensure that the password policy for your user pool requires a number",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Cognito user pool password policy requires at least one number",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices",
|
||||
"TTPs/Credential Access"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "Checks whether the password policy for your user pool requires a number.",
|
||||
"Risk": "If the password policy for your user pool does not require a number, the user pool is less secure and more vulnerable to attacks.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html",
|
||||
"Description": "Amazon Cognito user pools are evaluated for a password policy that **requires at least one number**. The assessment checks whether the policy enforces a numeric character via `RequireNumbers` and also identifies pools with no password policy configured.",
|
||||
"Risk": "Absent a numeric requirement-or any password policy-reduces password entropy, enabling **brute force** and **credential stuffing**. Successful account takeover grants valid tokens to protected APIs, risking data **confidentiality**, unauthorized actions affecting **integrity**, and resource abuse impacting **availability**.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html",
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/managing-users-passwords.html",
|
||||
"https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-cognito-userpool-passwordpolicy.html",
|
||||
"https://support.icompaas.com/support/solutions/articles/62000233673-ensure-that-the-password-policy-for-your-user-pool-requires-a-number"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"CLI": "aws cognito-idp update-user-pool --user-pool-id <USER_POOL_ID> --policies '{\"PasswordPolicy\":{\"RequireNumbers\":true}}'",
|
||||
"NativeIaC": "```yaml\n# CloudFormation: Set password policy to require at least one number\nResources:\n <example_resource_name>:\n Type: AWS::Cognito::UserPool\n Properties:\n Policies:\n PasswordPolicy:\n RequireNumbers: true # Critical: enforces at least one numeric character in passwords\n```",
|
||||
"Other": "1. In the AWS Console, go to Amazon Cognito > User pools\n2. Select your user pool\n3. Open Authentication (or Password policy) settings\n4. Enable Requires at least one number (Require numbers)\n5. Save changes",
|
||||
"Terraform": "```hcl\n# Terraform: Enable number requirement in Cognito password policy\nresource \"aws_cognito_user_pool\" \"<example_resource_name>\" {\n name = \"<example_resource_name>\"\n\n password_policy {\n require_numbers = true # Critical: enforces at least one numeric character in passwords\n }\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "To require a number in the password policy for your user pool, perform the following actions:",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html"
|
||||
"Text": "Enforce a strong password policy: require numbers (`RequireNumbers=true`), adequate length (e.g., `>=8`), and mixed case/symbols. Complement with **MFA**, login throttling/lockout, and password reuse limits for **defense in depth**. Apply **least privilege** to applications using tokens and monitor authentication activity.",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_password_policy_number"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"identity-access"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+24
-14
@@ -1,30 +1,40 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_password_policy_symbol",
|
||||
"CheckTitle": "Ensure that the password policy for your Amazon Cognito user pool requires at least one symbol.",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Cognito user pool password policy requires at least one symbol",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices",
|
||||
"TTPs/Credential Access"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "Check whether the password policy for your Amazon Cognito user pool requires at least one symbol.",
|
||||
"Risk": "If the password policy for your Amazon Cognito user pool does not require at least one symbol, it can be easier for attackers to crack passwords.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html",
|
||||
"Description": "**Amazon Cognito user pool** password policy includes a **symbol requirement** for user passwords.\n\nAssesses the presence of a policy and whether `require_symbols` is configured.",
|
||||
"Risk": "Absent a **symbol requirement**, passwords have lower entropy, increasing success of **brute force** and **credential stuffing**.\n\nCompromised accounts enable unauthorized token issuance, data access, and profile changes, impacting **confidentiality** and **integrity** across apps relying on the pool.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html",
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/managing-users-passwords.html"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"CLI": "aws cognito-idp update-user-pool --user-pool-id <example_resource_id> --policies \"PasswordPolicy={RequireSymbols=true}\"",
|
||||
"NativeIaC": "```yaml\n# CloudFormation: ensure Cognito User Pool requires at least one symbol in passwords\nResources:\n <example_resource_name>:\n Type: AWS::Cognito::UserPool\n Properties:\n Policies:\n PasswordPolicy:\n RequireSymbols: true # Critical: enforce at least one symbol to pass the check\n```",
|
||||
"Other": "1. Open the Amazon Cognito console and go to User pools\n2. Select the target user pool\n3. Go to Authentication (or Sign-in experience) > Password policy\n4. Enable Require special characters (Require symbols)\n5. Click Save changes",
|
||||
"Terraform": "```hcl\n# Terraform: ensure Cognito User Pool requires at least one symbol in passwords\nresource \"aws_cognito_user_pool\" \"<example_resource_name>\" {\n name = \"<example_resource_name>\"\n\n password_policy {\n require_symbols = true # Critical: enforce at least one symbol to pass the check\n }\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "To require at least one symbol in the password policy for your Amazon Cognito user pool, you can use the AWS Management Console or the AWS CLI.",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html"
|
||||
"Text": "Enforce a strong **password complexity** policy with `require_symbols=true`, adequate length, and mixed character sets. Combine with **MFA**, throttling or lockout, and credential hygiene to reduce takeover risk. Apply **defense in depth** and **least privilege** to limit blast radius if an account is compromised.",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_password_policy_symbol"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"identity-access"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+26
-14
@@ -1,30 +1,42 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_password_policy_uppercase",
|
||||
"CheckTitle": "Ensure that the password policy for your user pool requires at least one uppercase letter",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Cognito user pool password policy requires at least one uppercase letter",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/NIST 800-53 Controls (USA)",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/NIST CSF Controls (USA)",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/PCI-DSS",
|
||||
"TTPs/Initial Access"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "User pools allow you to configure a password policy for your user pool to specify requirements for user passwords. You can require that passwords have a minimum length, contain at least one uppercase letter, and contain at least one number. You can also require that passwords have at least one special character. You can also set the password policy to require that passwords be case-sensitive.",
|
||||
"Risk": "If the password policy for your user pool does not require at least one uppercase letter, it may be easier for an attacker to guess or crack user passwords.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html",
|
||||
"Description": "Amazon Cognito user pool password policy is evaluated for an uppercase character requirement (`require_uppercase`). The check also identifies user pools that have no password policy configured.",
|
||||
"Risk": "Missing an **uppercase requirement** lowers password entropy, easing **password spraying**, **brute force**, and offline cracking. Account takeover risks user data (**confidentiality**), enables unauthorized changes (**integrity**), and may disrupt services through abuse or lockouts (**availability**).",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"CLI": "aws cognito-idp update-user-pool --user-pool-id <USER_POOL_ID> --policies PasswordPolicy={RequireUppercase=true}",
|
||||
"NativeIaC": "```yaml\n# CloudFormation to require uppercase in Cognito User Pool password policy\nResources:\n <example_resource_name>:\n Type: AWS::Cognito::UserPool\n Properties:\n Policies:\n PasswordPolicy:\n RequireUppercase: true # Critical: enforce at least one uppercase letter\n```",
|
||||
"Other": "1. Open the Amazon Cognito console and go to User pools\n2. Select your user pool\n3. Go to Authentication methods (or Sign-in experience) > Password policy\n4. Check Requires at least one uppercase letter\n5. Click Save changes",
|
||||
"Terraform": "```hcl\n# Require uppercase in Cognito User Pool password policy\nresource \"aws_cognito_user_pool\" \"<example_resource_name>\" {\n name = \"<example_resource_name>\"\n\n password_policy {\n require_uppercase = true # Critical: enforce at least one uppercase letter\n }\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "To require that the password policy for your user pool requires at least one uppercase letter, you can use the AWS Management Console or the AWS CLI. For more information, see the documentation on user pool settings and policies.",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html"
|
||||
"Text": "Enforce a **strong password policy** requiring **uppercase characters**, sufficient `minimum_length`, and diverse character sets. Layer defenses: **MFA**, **rate limiting/lockout**, and **password reuse history**. *Where feasible*, prefer long passphrases and monitor authentication events to prevent account takeover.",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_password_policy_uppercase"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"identity-access"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+25
-14
@@ -1,30 +1,41 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_self_registration_disabled",
|
||||
"CheckTitle": "Ensure self registration is disabled for Amazon Cognito User Pools",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Amazon Cognito user pool has self registration disabled",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices",
|
||||
"TTPs/Initial Access"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "Checks whether self registration is disabled for the Amazon Cognito User Pool. Self registration allows users to sign up for an account in the user pool. If self registration is enabled, users can sign up for an account in the user pool without any intervention from the administrator. This can lead to unauthorized access to the application.",
|
||||
"Risk": "If self registration is enabled, users can sign up for an account in the user pool without any intervention from the administrator. This can lead to unauthorized access to the application.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito-user-identity-pools/latest/APIReference/API_SignUp.html",
|
||||
"Description": "**Amazon Cognito user pools** are evaluated for **self-service sign-up**. The expected configuration is `AllowAdminCreateUserOnly=true` so only administrators create accounts.\n\n*When self sign-up is allowed*, the check also highlights any linked identity pools and the authenticated role(s) that new users could assume.",
|
||||
"Risk": "Open sign-up lets untrusted users gain **authenticated identities**, potentially assuming **identity pool roles**. This can expose data (**confidentiality**), enable unauthorized actions (**integrity**), and drive abuse or cost via resource use (**availability**). Mass registrations and token harvesting increase the chance of lateral access.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/signing-up-users-in-your-app.html",
|
||||
"https://docs.amazonaws.cn/en_us/cognito/latest/developerguide/signing-up-users-in-your-app.html",
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-admin-create-user-policy.html"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"CLI": "aws cognito-idp update-user-pool --user-pool-id <USER_POOL_ID> --admin-create-user-config AllowAdminCreateUserOnly=true",
|
||||
"NativeIaC": "```yaml\n# CloudFormation: Disable self-registration in a Cognito User Pool\nResources:\n <example_resource_name>:\n Type: AWS::Cognito::UserPool\n Properties:\n AdminCreateUserConfig:\n AllowAdminCreateUserOnly: true # Critical: disables self sign-up; only admins can create users\n```",
|
||||
"Other": "1. Open the AWS Console and go to Amazon Cognito > User pools\n2. Select the user pool\n3. Go to the Sign-up tab\n4. In Self-service sign-up, click Edit and disable (uncheck) Enable self-registration\n5. Click Save changes",
|
||||
"Terraform": "```hcl\n# Terraform: Disable self-registration in a Cognito User Pool\nresource \"aws_cognito_user_pool\" \"<example_resource_name>\" {\n admin_create_user_config {\n allow_admin_create_user_only = true # Critical: disables self sign-up; only admins can create users\n }\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "To disable self registration for the Amazon Cognito User Pool, perform the following actions:",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/signing-up-users-in-your-app.html"
|
||||
"Text": "Enforce **admin-only user creation**. If self sign-up is necessary, require **verification**, **MFA**, and bot protections; restrict app clients. Apply **least privilege** to any roles for authenticated users and minimize scopes. Use approval/invite flows, add **rate limits**, monitor sign-ups, and audit access for **defense in depth**.",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_self_registration_disabled"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"identity-access"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+23
-14
@@ -1,30 +1,39 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_temporary_password_expiration",
|
||||
"CheckTitle": "Ensure that the user pool has a temporary password expiration period of 7 days or less",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Cognito user pool has temporary password expiration set to 7 days or less",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"TTPs/Initial Access",
|
||||
"TTPs/Credential Access"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
"ResourceType": "Other",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "Temporary passwords are set by the administrator and are used to allow users to sign in and change their password. Temporary passwords are valid for a limited period of time, after which they expire. Temporary passwords are used when an administrator creates a new user account or resets a user password. The temporary password expiration period is the length of time that the temporary password is valid. The default value is 7 days. You can set the expiration period to a value between 0 and 365 days.",
|
||||
"Risk": "If the temporary password expiration period is too long, it increases the risk of unauthorized access to the user account. If the temporary password expiration period is too short, it increases the risk of users being unable to sign in and change their password.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html",
|
||||
"Description": "**Amazon Cognito user pools** use **administrator-issued temporary passwords**. This evaluates whether a user pool defines a **password policy** and sets the temporary password validity to `7 days` or fewer.",
|
||||
"Risk": "**Long-lived temporary passwords** or an **absent policy** expand the window for credential reuse or interception. An attacker who obtains a temp password can complete first sign-in and set a new secret, enabling account takeover, unauthorized data access, and changes that impact confidentiality and integrity.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"CLI": "aws cognito-idp update-user-pool --user-pool-id <example_resource_id> --policies \"PasswordPolicy={TemporaryPasswordValidityDays=7}\"",
|
||||
"NativeIaC": "```yaml\n# CloudFormation: Set Cognito temporary password expiration to 7 days or less\nResources:\n <example_resource_name>:\n Type: AWS::Cognito::UserPool\n Properties:\n Policies:\n PasswordPolicy:\n TemporaryPasswordValidityDays: 7 # Critical: ensures temp passwords expire in 7 days (PASS)\n```",
|
||||
"Other": "1. Open the Amazon Cognito console and select **User pools**\n2. Choose your user pool\n3. Go to **Authentication** (or **Authentication methods**) > **Password policy**\n4. Set **Temporary passwords set by administrators expire in** to **7** (or fewer) days\n5. Click **Save changes**",
|
||||
"Terraform": "```hcl\n# Terraform: Set Cognito temporary password expiration to 7 days or less\nresource \"aws_cognito_user_pool\" \"<example_resource_name>\" {\n name = \"<example_resource_name>\"\n\n password_policy {\n temporary_password_validity_days = 7 # Critical: 7 or less to pass the check\n }\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Set the temporary password expiration period to 7 days or less.",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-settings-policies.html"
|
||||
"Text": "Define a **password policy** with temporary password validity `<= 7 days` (use the shortest practical). Require change on first sign-in, enable **MFA** during enrollment, and deliver secrets via secure channels. Apply **least privilege** and revoke or reissue unused temporary credentials promptly.",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_temporary_password_expiration"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"identity-access"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
+24
-14
@@ -1,30 +1,40 @@
|
||||
{
|
||||
"Provider": "aws",
|
||||
"CheckID": "cognito_user_pool_waf_acl_attached",
|
||||
"CheckTitle": "Ensure that Amazon Cognito User Pool is associated with a WAF Web ACL",
|
||||
"CheckType": [],
|
||||
"CheckTitle": "Amazon Cognito user pool is associated with a WAF Web ACL",
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/AWS Security Best Practices",
|
||||
"Industry and Regulatory Standards/AWS Foundational Security Best Practices",
|
||||
"Effects/Denial of Service"
|
||||
],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
"ResourceType": "AwsWafv2WebAcl",
|
||||
"ResourceGroup": "IAM",
|
||||
"Description": "Web ACLs are used to control access to your content. You can use a Web ACL to control who can access your content. You can also use a Web ACL to block requests based on IP address, HTTP headers, HTTP body, URI, or URI query string parameters. You can associate a Web ACL with a Cognito User Pool to control access to your content.",
|
||||
"Risk": "If a Web ACL is not associated with a Cognito User Pool, then the content is not protected by the Web ACL. This could lead to unauthorized access to your content.",
|
||||
"RelatedUrl": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-waf.html",
|
||||
"Description": "Amazon Cognito user pools are evaluated for an association with an **AWS WAFv2 web ACL** that filters and controls requests to the hosted UI and public user pool API endpoints.",
|
||||
"Risk": "Without a web ACL, Cognito endpoints lack layer-7 filtering, enabling:\n- Credential stuffing and account enumeration\n- Bot abuse and high-rate requests degrading service\n- Malicious payload probes\n\nThis threatens **availability**, risks unauthorized access to user data (**confidentiality**), and undermines session **integrity**.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-waf.html"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "",
|
||||
"Terraform": ""
|
||||
"CLI": "aws wafv2 associate-web-acl --web-acl-arn <WEB_ACL_ARN> --resource-arn <COGNITO_USER_POOL_ARN>",
|
||||
"NativeIaC": "```yaml\nResources:\n <example_resource_name>:\n Type: AWS::WAFv2::WebACLAssociation\n Properties:\n ResourceArn: <example_resource_arn> # Critical: Cognito User Pool ARN to protect\n WebACLArn: <example_web_acl_arn> # Critical: WAF Web ACL ARN to associate\n```",
|
||||
"Other": "1. Open the AWS Console and go to Cognito > User pools\n2. Select the user pool\n3. In Security, open the AWS WAF tab and click Edit\n4. Check Use AWS WAF with your user pool\n5. Select the existing regional Web ACL\n6. Click Save changes",
|
||||
"Terraform": "```hcl\nresource \"aws_wafv2_web_acl_association\" \"<example_resource_name>\" {\n resource_arn = \"<example_resource_arn>\" # Critical: Cognito User Pool ARN\n web_acl_arn = \"<example_web_acl_arn>\" # Critical: WAF Web ACL ARN\n}\n```"
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "The Web ACL should be associated with the Cognito User Pool. To associate a Web ACL with a Cognito User Pool, use the AWS Management Console.",
|
||||
"Url": "https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-waf.html"
|
||||
"Text": "Associate an **AWS WAFv2 web ACL** with each user pool to enforce layer-7 controls. Use defense-in-depth: managed rule groups, `rate-based` limits, IP reputation, and bot mitigation. Enable request logging and continuously tune rules to reduce false positives. *Avoid rule sets incompatible with Cognito endpoints.*",
|
||||
"Url": "https://hub.prowler.com/check/cognito_user_pool_waf_acl_attached"
|
||||
}
|
||||
},
|
||||
"Categories": [],
|
||||
"Categories": [
|
||||
"threat-detection",
|
||||
"internet-exposed"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
"Notes": ""
|
||||
|
||||
Reference in New Issue
Block a user