wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
303 stars 61 forks source link

[Contribution] GCP Identity-Aware Proxy Misconfiguration #269

Open korniko98 opened 7 months ago

korniko98 commented 7 months ago

Summary (give a brief description of the issue)

Researcher found a way to disclose any user email address via CORS misconfiguration in IAP by opening a malicious domain, and implemented two different attack scenarios to read the email address of an authenticated or unauthenticated user.

References (provide links to blogposts, etc.)

https://medium.com/@LogicalHunter/identity-aware-proxy-misconfiguration-google-cloud-vulnerability-813d2a07a4ed