Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3147Cross-tenant Cloud Function compromise via storage bucket squatting Cross-tenant vulnerability Google Anthony Weems Bug Bounty2020-09-202023-06-13
2091ChaosDB Explained: Azure%27s Cosmos DB Vulnerability Walkthrough Cross-tenant vulnerability Account takeover Privilege escalation Microsoft Nir Ohfeld (@nirohfeld) Bug Bounty2021-11-102023-06-13
1760AutoWarp: Critical Cross-Account Vulnerability in Microsoft Azure Automation Service Cross-tenant vulnerability Account takeover Microsoft Yanir Tsarimi (@Yanir_) Bug Bounty2022-03-072023-06-13
1591Wiz Research discovers "ExtraReplica"— a cross-account database vulnerability in Azure PostgreSQL Cross-tenant vulnerability Privilege escalation Authentication bypass Cloud Microsoft Shir Tamari (@shirtamari) Bug Bounty2022-04-282023-06-13
1470SynLapse – Technical Details for Critical Azure Synapse Vulnerability Cross-tenant vulnerability RCE Cloud Microsoft Tzah Pahima (@TzahPahima) Bug Bounty2022-06-142023-06-13
1419FabricScape: Escaping Service Fabric and Taking Over the Cluster Container escape Local Privilege Escalation Cross-tenant vulnerability Microsoft Unit 42 (@Unit42_Intel) Bug Bounty2022-06-282023-06-13
1246The cloud has an isolation problem: PostgreSQL vulnerabilities affect multiple cloud vendors Privilege escalation Cross-tenant vulnerability OS command injection Local Privilege Escalation Cloud Google Microsoft Aiven Shir Tamari (@shirtamari) Bug Bounty2022-08-112023-06-13
1060AttachMe: critical OCI vulnerability allows unauthorized access to customer cloud storage volumes Cloud Cross-tenant vulnerability Authorization flaw Oracle Elad Gabay (@eladgabay_) Bug Bounty2022-09-202023-06-13
659ACSESSED: Cross-tenant network bypass in Azure Cognitive Search Cloud Cross-tenant vulnerability Privilege escalation Microsoft (Azure) Emilien Socchi (@emiliensocchi) Bug Bounty2022-12-222023-06-13
251Riding the Azure Service Bus (Relay) into Power Platform RCE Cross-tenant vulnerability Cloud Insecure deserialization Microsoft (Azure) Nick Landers (@monoxgas) Bug Bounty2023-03-302023-06-13
236Two Minor Cross-Tenant Vulnerabilities in AWS App Runner Cross-tenant vulnerability Cloud AWS Nick Frichette (@frichette_n) Bug Bounty2023-04-032023-06-13
182#BrokenSesame: Accidental write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services Cloud RCE Container escape Kubernetes Privilege escalation Lateral movement Supply chain attack Cross-tenant vulnerability Alibaba Ronen Shustin (@ronenshh) Bug Bounty2023-04-192023-06-13