2022-03-09 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Azure Logic Apps use API Connections to authenticate actions to services. Having Contributor access to an Azure Resource Manager (ARM) API Connection would allow someone to create arbitrary role assignments as the connected user. This was supposed to be limited to actions at the Resource Group level, but an attacker could escape to the Subscription or Root level with a path traversal payload. The root cause of this behavior was that such a payload would meet the Swagger API definition, and it w…
P10
2022-03-07 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An exposed endpoint in the Azure Automation Service allowed to steal Azure API credentials from other customers
P0
2022-02-24 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Cloud Armor has a documented limitation of 8 KB as the maximum size of web request that it will inspect. The default behavior of Cloud Armor in this case can allow oversized malicious requests to bypass Cloud Armor and directly reach an underlying application. Moreover, Cloud Armor does not warn users of this limitation during policy creation or when configuring rules from within the web UI, and can only find a reference to the 8 KB limit in the [Cloud Armor documentation](https://cloud.google.…
P0
2022-02-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Opsmorph discovered an improper access control vulnerability in authorization logic common in applications built on AWS. The vulnerability means a user with permission to create a new Cognito User Group could fool authorization checks into thinking that the user is in any other existing Cognito User Group in the same User Pool, referred to as user group spoofing. When API Gateway is secured with a Cognito User Pool Authorizer it concatenates group names from the identity token into a comma sepa…
P0
2022-02-03 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
When customers attach a CodeBuild project to their VPC, CodeBuild’s build container will apply the same network routing rules as defined in the customer’s VPC Security Group. However, CodeBuild EC2 hosts retained Internet connectivity via AWS's own VPC, thus allowing an attacker to bypass any custom VPC rules the customer had set up, and use CodeBuild for data exfiltration from the targeted environment. AWS later updated the CodeBuild service to block all outbound network access for newly creat…
P0
2022-01-13 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Read access of host of AWS internal Cloudformation service via XXE SSRF. The level of access with the compromised IAM role from there is unclear.
P0
2022-01-13 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Compromise of internal AWS Glue service to assume the glue role in any AWS account that used glue.
P0
2022-01-06 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Use of the AI services on AWS allows customer data to be moved outside of the regions it is used in and potentially shared with third-parties. Note: This issue is outside the scope of this database's usual criteria for inclusion, but has been kept for historic reasons, as it was included in the original CSP Security Mistakes dataset.
P0
2021-12-30 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Google Cloud Platform's Identity-Aware Proxy (IAP) allowed attackers to bypass authentication and access IAP-secured web applications. The exploit involved creating a malicious IAP-secured app using the target's OAuth client ID, configuring query parameter-based routing to capture redirect tokens, and using these tokens to hijack authorized sessions.
P0
2021-12-28 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability was discovered in Cloud Shell that enabled command injection and remote shell access. The "Open in Cloud Shell" functionality allowed a user to provide values for both the "git_repo" and "go_get_repo" parameters, which would clone the target repo in the user's environment. While "git_repo" was validated against a list of trusted repos, "go_get_repo" was not. Therefore, an attacker could have supplied a trusted repository as "git_repo" and an arbitrary command in the "go_get_repo…
P0
2021-12-22 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS added an excessive s3:getObject permission to AWSSupportServiceRolePolicy IAM policy used by AWS Support teams, and removed it a day later.
P0
2021-12-07 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Several cloud desktop solutions rely on a 3rd-party library called Eltima SDK to provide USB over Ethernet capabilities, to allow users to connect and share local devices such as webcams. SentinelLabs discovered vulnerabilities in Eltima drivers, including proprietary versions used by several cloud services (among them AWS Workspaces), that would allow unprivileged users to escalate privileges to kernel mode.
P0
2021-12-02 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS SageMaker Notebook server lacked a check of the Origin header that led to a CSRF vulnerability. An attacker could have read sensitive data and execute arbitrary actions in customer environments. The exact same issue existed in GCP previously.
P0
2021-11-17 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Automation Account 'Run as' credentials (PFX certificates) were being stored in cleartext, in Azure Active Directory (AAD). These credentials were available to anyone with the ability to read information about App Registrations (typically most AAD users).
P0
2021-11-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Information about this issue is under NDA, but AWS customers can read about it on page 98 of the report, which is available for download through AWS Artifact. Note: This issue is outside the scope of this database's usual criteria for inclusion, but has been kept for historic reasons, as it was included in the original CSP Security Mistakes dataset.
P0
2021-11-10 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A flaw in AWS API Gateway enabled hiding HTTP request headers. Tampering with HTTP requests visibility enabled bypassing IP restrictions, cache poisoning and request smuggling.
P0
2021-10-18 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Multiple vulnerabilities were found in Google Cloud SQL, including config file injection leading to RCE, information disclosure in the Cloud SQL Auth Proxy, and a design issue in Postgres IAM authentication allowing access token theft. Other issues included GCR permission misconfigurations and potential for terminal escape sequence injection attacks via gcloud.
P0
2021-10-07 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Azure App Service had an insecure default behavior that exposed the source code of customer applications written in PHP, Python, Ruby, or Node, that were deployed using “Local Git”.
P0
2021-09-29 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Azure Active Directory Seamless Single Sign-On feature allowed single-factor brute-force attacks against Azure AD without generating sign-in events in the targeted organization’s tenant.
P0
2021-09-29 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
There is a known issue where updating a BackendConfig resource using the v1beta1 API removes an active Google Cloud Armor security policy from its service. If you do not configure Google Cloud Armor on your Ingress resources via the BackendConfig, then this issue does not affect your clusters.
P0
2021-09-21 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
If a user with AWS WorkSpaces 3.0.10-3.1.8 installed visits a page in their web browser with attacker controlled content, the attacker can get zero click RCE under common circumstances.
P15
2021-09-13 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Azure AD users could escalate their privileges using the Log Analytics Contributor role to reach the full Subscription Contributor role.
P10
2021-09-09 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Cross-account container escape
P0
2021-08-26 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Azure's Cosmos DB database service was vulnerable to remote account takeover. Any Azure user could gain full admin access to other customers' Cosmos DB instances without authorization. The vulnerability had a trivial exploit that doesn't require any previous access to the target environment.
P0
2021-06-13 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A privilege escalation vulnerability was discovered in Google's Dialogflow cloud platform. When downgrading a user's role from Developer to Reviewer, the permissions were not properly updated, allowing the user to retain Developer-level access. This issue persisted in the Google Cloud Console, where role changes resulted in additive permissions instead of replacements.
P10
2021-06-01 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Azure forces the install of an agent on Linux VMs, which contained a vulnerability that would grant root RCE if an attacker could send a web request to them. Initially, Microsoft did not update the agent automatically, and so customers had to patch manually, but a few days later they began patching some services remotely.
P15
2021-04-30 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in AWS Cognito's password reset function allowed attackers to brute-force the six-digit reset code, potentially leading to account takeovers. Using concurrent HTTP requests, an attacker could make up to 1587 guesses instead of the documented limit of 20. The issue affected accounts without multi-factor authentication and was fixed by AWS on April 20, 2021.
P0
2021-03-10 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
If attacker controlled data is viewed in Cloudshell it could have led to code execution. This exact same issue existed in Azure previously.
P0
2021-03-09 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in the Azure Linux VM extension mechanism allowed an unprivileged user to leak any Azure VM extension’s private data. An attacker could have abused this to gain credentials for the VM itself as well as credentials for extensions associated with the VM. Paired with the design of the VMAccess extension (an official Azure extension for managing VM credentials), this could have been used to achieve privilege escalation, as an unprivileged attacker would have been able to elevate the…
P10
2021-02-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An attacker could gain root privileges on their Azure Cloud Shell container, escape from the container, and then gain root privileges on the underlying node, the root cause being an insecure kubelet port (10250), among other cluster misconfigurations. Once they could access the node filesystem, an attacker could extract kubelet API credentials which allowed listing all pods and nodes in the cluster, including those belonging to other tenants. Moreover, an attacker could bypass RBAC policies in …
P0