wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
303 stars 61 forks source link

[Contribution] Information Disclosure Vulnerability in the Google Cloud Speech-to-Text API #233

Closed korniko98 closed 11 months ago

korniko98 commented 11 months ago

Summary (give a brief description of the issue)

A vulnerability was discovered in the Google Cloud Speech-to-Text API that allowed a user to read transcription results belonging to a different, unrelated user. This vulnerability could be exploited with a simple “curl” command.

References (provide links to blogposts, etc.)

https://www.dcine.com/2020/01/12/information-disclosure-vulnerability-in-the-google-cloud-speech-to-text-api/