← Back to feed
Vulnerabilities & PatchesEmerging1 sourceNov 18, 2021 · 04:05via API Security News

Issue 160: Vulnerability in AWS API gateway, Kubernetes API access hardening guide

Brief

This week, we have a vulnerability in the AWS API gateway that allows a potential cache-poisoning attack, disclosed at the recent BlackHat Europe conference, a guide on how to harden Kubernetes API access, a report from Forbes on the need to take API security more seriously, and predictions on what’s possibly on the next OWASP API security Top 10.

Vulnerability: AWS API gateway vulnerable to HTTP header-smuggling attack

At the recent BlackHat Europe security conference, web security researcher Daniel Thatcher disclosed vulnerabilities relating to the AWS API gateway that allowed HTTP header smuggling. Currently, AWS has not responded to this research nor offered a comment regarding the potential vulnerabilities in their API gateway.

Read more on API Security News