wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
303 stars 61 forks source link

[Contribution] Command Injection in Google Cloud Shell #236

Closed korniko98 closed 8 months ago

korniko98 commented 11 months ago

Summary (give a brief description of the issue)

The researcher managed to bypass one of the main security boundaries in the “Open in Cloud Shell” feature from the Google Cloud Shell and discovered that it could be abused to access the user’s GCP resources.

References (provide links to blogposts, etc.)

https://docs.google.com/document/d/1-TTCS6fS6kvFUkoJmX4Udr-czQ79lSUVXiWsiAED_bs/edit#heading=h.p3l0lr3qhjty