Issue 168: Safari 15 IndexedDB API vulnerability, a pair of AWS vulnerabilities, and an API security podcast
Brief
This week, we have news of a vulnerability in the IndexedDB API in Safari 15 that exposed user information, a pair of vulnerabilities in AWS affecting AWS Glue and AWS CloudFormation, and a podcast featuring Rinki Sethi and Alissa Knight discussing API security.
Last week, we featured an “awesome API security” guide from a 3rd-party site with good intentions. Subsequently, we’ve discovered that this guide is a direct and unattributed copy of the excellent guide by André Rainho previously featured in this newsletter . Our apologies to Andre for this oversight, and we strongly advise readers to check out his original Awesome API Security guide.
Vulnerability: Safari 15 leaks information through IndexedDB API
First up this week, we have news of a vulnerability in the IndexedDB API of the Safari 15 browser , disclosed by the team at FingerprintJS.
