high

Bypassing Identity-Aware Proxy in Google Cloud

Published Thu, Dec 30th, 2021

Platforms

gcp

Summary

A vulnerability in Google Cloud Platform's Identity-Aware Proxy (IAP) allowed attackers to bypass authentication and access IAP-secured web applications. The exploit involved creating a malicious IAP-secured app using the target's OAuth client ID, configuring query parameter-based routing to capture redirect tokens, and using these tokens to hijack authorized sessions.

Affected Services

Identity-Aware Proxy

Remediation

None required. The vulnerability has been fixed by Google.

Tracked CVEs

No tracked CVEs

References

Contributed by https://github.com/korniko98

Entry Status

Stub (AI-Generated)

Disclosure Date

Wed, May 5th, 2021

Exploitability Period

Until 2021/06

Known ITW Exploitation

-

Detection Methods

Monitor for unauthorized access to IAP-secured applications. Review IAP logs for suspicious authentication attempts or unexpected redirect patterns.

Piercing Index Rating

-

Discovered by

SebLu