aws-appsync-iot-core-realtime-example
aws-appsync-iot-core-realtime-example copied to clipboard
Risk: over-authorization of AWS IoT policy
We are a security research team and we recently discovered that there is an over-authorization security issue with this project's IoT policy. The affected file is as following:
1. aws-appsync-iot-core-realtime-example/sensor/policy.json