high

Google App Engine RCE Worth $36k

Published Sat, Aug 31st, 2019
Platforms

Summary

Researcher discovered access to non-production Google App Engine environments and internal APIs. This allowed configuring internal settings like Service Account IDs and quotas. Google considered it RCE due to their infrastructure. Access was blocked and a $36,337 reward issued.

Affected Services

App Engine

Remediation

None required

Tracked CVEs

No tracked CVEs

References

Entry Status
Stub (AI-Generated)
Disclosure Date
Sun, Feb 25th, 2018
Exploitablity Period
Until 2018/03/13
Known ITW Exploitation
-
Detection Methods
Monitor for unexpected access attempts to non-production App Engine environments. Review App Engine configuration changes, especially around Service Accounts and quotas.
Piercing Index Rating
-
Discovered by
Ezequiel Pereira