Collected research
#341876 SSRF in Exchange leads to ROOT access in all instances
Shopify disclosed on HackerOne: SSRF in Exchange leads to ROOT...
A store template on Shopify Exchange made the screenshot renderer fetch Google Cloud metadata, and the v1beta1 endpoint returned the instance service-account token without the usual Metadata-Flavor header. The leaked kube-env attribute yielded Kubelet certificates, which gave pod secrets and a root shell in any container of that infrastructure subset.
Record
- Document
- Shopify disclosed on HackerOne: SSRF in Exchange leads to ROOT...
- Researcher
- André Baptista
- Published by
- HackerOne
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of André Baptista, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .