google-drive

1 article
sort: new top best
clear filter
0 8/10

A researcher discovered an SSRF vulnerability in Vimeo's file upload function by exploiting partial content transfer using HTTP Range headers. By manipulating redirect responses during the chunked file download process, they were able to retrieve sensitive Google Cloud metadata and API tokens.

Vimeo Sayed Abdelhafiz HackerOne Google Drive Google Cloud metadata.google.internal
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details