wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
303 stars 61 forks source link

[Contribution] Delefriend #257

Open korniko98 opened 9 months ago

korniko98 commented 9 months ago

Summary (give a brief description of the issue)

References (provide links to blogposts, etc.)

https://www.hunters.security/en/blog/delefriend-a-newly-discovered-design-flaw-in-domain-wide-delegation-could-leave-google-workspace-vulnerable-for-takeover https://unit42.paloaltonetworks.com/critical-risk-in-google-workspace-delegation-feature/ https://medium.com/@lutzenfried/gcp-domain-wide-delegation-abuses-b82b8dd8cf15