Published Mon, Dec 16th, 2019
Platforms
Wouter ter Maat discovered 9 vulnerabilities in GCP Cloudshell that could allow an attacker to access resources in another customer's environment.
Cloudshell
None required
No tracked CVEs
Contributed by https://github.com/korniko98
Entry Status
Finalized
Disclosure Date
Mon, Dec 16th, 2019
Exploitability Period
-
Known ITW Exploitation
-
Detection Methods
None
Piercing Index Rating
-
Discovered by
Wouter ter Maat, Offensi
ALBs found vulnerable to HTTP request smuggling (desync attack).