wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
303 stars 61 forks source link

[Contribution] RCE on Apigee API proxies #237

Closed korniko98 closed 11 months ago

korniko98 commented 11 months ago

Summary (give a brief description of the issue)

The researcher managed to gain root privileges in an Apigee instance, but Google responded to the bug report saying that the code execution was sandboxed, so there seems to be no impact and therefore I'm creating an issue just so we have a record of this.

References (provide links to blogposts, etc.)

https://omespino.com/write-up-google-vrp-n-a-sandboxed-rce-as-root-on-apigee-api-proxies/