wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
306 stars 61 forks source link

[Contribution] Bypassing Identity-Aware Proxy #225

Open korniko98 opened 1 year ago

korniko98 commented 1 year ago

Summary (give a brief description of the issue)

The researcher discovered a way, how an attacker could leak tokens from other users who are authorized to access an IAP-secured web application. This allows an attacker to hijack sessions and hence access IAP-secured web applications.

References (provide links to blogposts, etc.)

https://www.seblu.de/2021/12/iap-bypass.html