Collected research
Auth bypass: Leaking Google Cloud service accounts and projects
Finds that a forged Google Cloud pagination token can select a different project from the project named in the authorized request path. The mismatch leaks service-account metadata from arbitrary projects and permits enumeration through predictable Google-managed accounts.
Record
- Researcher
- Ezequiel Pereira
- Published by
- Ezequiel Pereira
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Ezequiel Pereira, first published at the original source. Preserved copies are kept so the citation survives its host.