google-app-engine

2 articles
Sort: New Top Best
clear filter
0

A researcher discovered a Server-Side Request Forgery (SSRF) vulnerability in Google Sites' Caja server that allowed fetching arbitrary resources from Google's internal Borg cluster management network, exposing sensitive information about internal infrastructure including job details, system users, and resource allocation. The vulnerability was reported to Google's VRP and patched within 48 hours.

Google Google Sites Google Caja Google App Engine Borg Kubernetes Gvisor Google VRP MapReduce BitTable Flume GFS
opnsec.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0 1/10

A brief mention of a $36,000 bug bounty for a remote code execution vulnerability in Google App Engine, but with no technical details provided.

Google Google App Engine
sites.google.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details