Researcher finds SSRF bug in internal Google Cloud project, nabs $10,000 bounty

Discussion in 'other security issues & news' started by guest, Nov 19, 2021.

  1. guest

    guest Guest

    Researcher finds SSRF bug in internal Google Cloud project, nabs $10,000 bounty
    Now-patched API vulnerability allowed attacker to access sensitive resources
    November 19, 2021
    https://portswigger.net/daily-swig/...ernal-google-cloud-project-nabs-10-000-bounty
    URL whitelist bypass in https://cxl-services.appspot.com
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.