Web Hack List

Collected research

#341876 SSRF in Exchange leads to ROOT access in all instances

Shopify disclosed on HackerOne: SSRF in Exchange leads to ROOT...

A store template on Shopify Exchange made the screenshot renderer fetch Google Cloud metadata, and the v1beta1 endpoint returned the instance service-account token without the usual Metadata-Flavor header. The leaked kube-env attribute yielded Kubelet certificates, which gave pod secrets and a root shell in any container of that infrastructure subset.

Record

Document
Shopify disclosed on HackerOne: SSRF in Exchange leads to ROOT...
Researcher
André Baptista
Published by
HackerOne
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of André Baptista, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .