2020-12-20 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Information about this issue is under NDA, but AWS customers can read about it on pages 120-121 of the report, which is available for download through AWS Artifact. Note: This issue is outside the scope of this database's usual criteria for inclusion, but has been kept for historic reasons, as it was included in the original CSP Security Mistakes dataset.
P0
2020-11-12 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An SSRF bug in Google Cloud Monitoring's uptime check feature could have been used to leak the authentication token of the service account used for these checks. The issue was resolved but later bypassed by Omar Espino (@omespino), requiring another fix.
P0
2020-10-19 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An attacker with sufficient privileges in AWS to modify the route table and some other EC2 privileges, could pretend to be a metadata server and provide an attacker controlled bootup script to EC2s to move laterally.
P0
2020-10-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS have released or changed managed IAM policies in unexpected and insecure ways. Examples include: CheesepuffsServiceRolePolicy, AWSServiceRoleForThorInternalDevPolicy, AWSCodeArtifactReadOnlyAccess.json, AmazonCirrusGammaRoleForInstaller. The worst being the ReadOnlyAccess policy having almost all privileges removed and unexpected ones added.
P0
2020-10-06 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Amazon Elastic Kubernetes Service (EKS) uses IAM to provide authentication to the cluster through the AWS IAM Authenticator for Kubernetes (aws-iam-authenticator). Multiple issues were identified in the authenticator that could have allowed exploitation, namely (1) a lax regular expression used to verify presigned URLs; (2) HTTP client redirect follow (due to using Golang HTTP client in its default configuration); (3) use of the Golang URL.Query function (which silently drops parameters that Go…
P0
2020-10-01 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Google Cloud Shell allowed escalation from XSS to full instance takeover as root. The attack exploited an XSS in the markdown preview functionality to read sensitive files, obtain the instance's private key and hostname, and gain SSH access as root. The issue affected the Eclipse Theia-based editor used in Cloud Shell.
P15
2020-09-28 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS KMS and all versions of AWS Encryption SDKs prior to version 2.0.0 were susceptible to information leakage (an attacker could create ciphertexts that would leak the user’s AWS account ID, encryption context, user agent, and IP address upon decryption), ciphertext forgery (an attacker could create ciphertexts that were accepted by other users) and lack of robustness (an attacker could create ciphertexts that decrypt to different plaintexts for different users).
P0
2020-09-25 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An audit of an AWS open-source project identified a great deal of issues, and as a result AWS made the decision to take it down.
P0
2020-09-22 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
CloudFormation allows the use of Lambda-backed resource providers, wherein Lambda can be used to write custom provisioning logic to be executed during CloudFormation stack operations. The aforementioned Lambda functions were executed in an AWS-managed account (thus effectively allowing arbitrary code execution in that account), and were passed a set of credentials ("platformCredentials") for a role in this account that had several EventBridge permissions. These were sufficient for an attacker t…
P0
2020-09-01 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An attacker with the ability to create CloudFormation stacks could cause a denial-of-service on some CloudFormation actions within a single AWS account.
P0
2020-08-18 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Researchers discovered vulnerabilities in Google Cloud SQL that allowed gaining unauthorized shell access to MySQL instances. By chaining SQL injection, parameter injection in mysqldump, and network spoofing, they were able to escape a Docker container and gain full access to the host VM running Cloud SQL.
P0
2020-08-18 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Three vulnerabilities in Google Cloud Shell were discovered, allowing attackers to execute arbitrary code and potentially steal user credentials. The bugs affected Ruby gemspec parsing, TypeScript plugin loading, and Go binary path manipulation in Cloud Run. These issues arose from mismatches between Cloud Shell's threat model and the assumptions of its underlying open-source components.
P0
2020-07-27 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Using CloudTrail S3 data events, it was possible to determine the AWS account ID of any existing S3 bucket by calling any S3 API, getting denied, and looking at the value in the resource key in error message that showed up in CloudTrail.
P0
2020-05-21 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An RCE in Google Cloud Deployment Manager could have allowed an attacker to make requests to internal Google services, authenticated as a privileged service account.
P15
2020-04-23 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
GuardDuty detected CloudTrail being outright disabled, but did not detect if an attacker with the necessary permissions filtered out all events from CloudTrail via PutEventSelectors, resulting in defenders having no logs to review. AWS fixed this issue by adding a GuardDuty detection that triggers if PutEventSelectors is used to disable all event types.
P0
2020-03-11 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Google Cloudshell leveraged websockets without validating that the origin matched the current instance host. An attacker could therefore host a CSWSH attack on a Cloudshell instance they own, disabling authentication via access to the underlying VM. They could then start the OAuth process with a spoofed host header, using phishing to get the target Cloud Shell user into following a redirection link, completing the OAuth process and ending in successful CSWSH, which would allow the attacker to h…
P0
2020-01-30 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A Vulnerability in App Service could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system, thereby escaping the sandbox. This vulnerability allowed cross-account access when using the Free/Shared tier.
P15
2020-01-23 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An AWS employee pushed sensitive data to a public github bucket, including customer information and credentials. Note: This issue is outside the scope of this database's usual criteria for inclusion, but has been kept for historic reasons, as it was included in the original CSP Security Mistakes dataset.
P0
2019-11-29 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability was discovered in Google Cloud Platform's AI Hub service, allowing unrestricted file uploads. This could potentially lead to bypassing Same-Origin Policy by uploading SWF files, enabling CSRF attacks across browsers, and exploiting CVE-2014-8453 on IE with Adobe Reader installed. The issue resulted in a $1337 bounty reward.
P5
2019-08-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Shortly after Lake Formation was made generally available, a bug was discovered that gave anyone the ability to view and override data lake admins for any account (an attacker would have only needed to know the target account number in advance). The root cause was in the Catalog ID, which references the Glue metadata store that Lake Formation uses to store its configuration - none of the methods that used this field actually checked for permissions on the account it was accessing, only the sour…
P0
2019-08-04 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS offers a metadata service accessible to most EC2 Instances via a simple GET request to 169.254.169.254. If an instance has an SSRF vulnerability, attackers can access the metadata service & exfiltrate the credentials of an attached IAM role to gain privileged access to the relevant AWS environment.
P0
2019-06-18 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
The AWS CodeStar service had an undocumented API (codestar:CreateProjectFromTemplate) that allowed users with broadly-scoped CodeStar permissions to create a CodeStar project. As part of the creation process, AWS would create a new CodeStarWorker IAM policy & attach it to the user making the call. This policy granted full access to over 50 AWS services, including iam:AttachRolePolicy, iam:AttachUserPolicy and iam:PutRolePolicy permissions, which would allow the user to escalate to full administ…
P10
2019-01-09 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
If attacker controlled data is viewed in Cloudshell it could have led to code execution. This exact same issue was later discovered in AWS as well.
P0
2018-08-10 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Patrick Hudak demonstrated possible subdomain takeover using the Traffic Manager in Azure.
P0
2018-05-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Even for the AWS-managed ElasticSearch clusters that had not been made public, their index names could be learned.
P0
2017-11-07 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS has previously provided managed policies or guidance in documentation for policies with mistakes that allow them to be bypassed. Additionally, some policies are over-privileged. Date of disclosure is for the first issue of this type, while references provide other examples by various individuals.
P0
2017-10-10 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
The AWS Java SDK was vulnerable to XML external entity (XXE) injection related to XML parsers.
P0
2016-11-26 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Full administrative access to the Azure Red Hat Enterprise Linux Appliance REST API was publicly exposed. It allowed malicious actors uploading packages that would be acquired by client virtual machines on their next yum update. The vulnerable infrastructure supplies all the packages for all Red Hat Enterprise Linux instances booted from the Azure marketplace.
P0
2016-11-16 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
3rd party vendors can (and sometimes do) incorrectly implement sts:ExternalId in their AWS role trust policies, leading to confused deputy issues. These misconfigurations could allow customers to access other customers' data. Although vendors are responsible for ensuring their own configurations are correct, AWS could theoretically add mitigations to prevent and detect this issue.
P0
2011-06-04 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Researchers, while investigating the security posture of Public AMIs, were able to undelete files from an official image that was published by Amazon AWS.
P0