writeups.xyz writeups.xyz / Microsoft (Azure)

Title Vulnerabilities Programs Authors
Escalating From Reader To Contributor In Azure API Management
GitHub Actions Exploitation: Repo Jacking And Environment Manipulation
These Services Shall Not Pass: Abusing Service Tags to Bypass Azure Firewall Rules (Customer Action Required)
Arbitrary 1-click Azure tenant takeover via MS application
So I Became A Node: Exploiting Bootstrap Tokens In Azure Kubernetes Service
FlowFixation: AWS Apache Airflow Service Takeover Vulnerability and Why Neglecting Guardrails Puts Major CSPs at Risk
All the Small Things: Azure CLI Leakage and Problematic Usage Patterns
What the Function: Decrypting Azure Function App Keys
Knocking on the Front Door (client side desync attack on Azure CDN)
Hijacking Cloud CI/CD Systems for Fun and Profit
Two XSS Vulnerabilities in Azure with Embedded postMessage IFrames
Tampering with Conditional Access Policies Using Azure AD Graph API
When Good APIs Go Bad: Uncovering 3 Azure API Management Vulnerabilities
From listKeys to Glory: How We Achieved a Subscription Privilege Escalation and RCE by Abusing Azure Storage Account Keys
Riding the Azure Service Bus (Relay) into Power Platform
Super FabriXss: From XSS to an RCE in Azure Service Fabric Explorer by Abusing an Event Tab Cluster Toggle (CVE-2023-23383)
Escalating Privileges with Azure Function Apps
Microsoft Azure Account Takeover via DOM-based XSS in Cosmos DB Explorer
Abusing Azure App Service Managed Identity Assignments
Technical Advisory – Azure B2C – Crypto Misuse and Account Compromise
Azure security — Internal recon leveraging lack of access control
EmojiDeploy: Smile! Your Azure web service just got RCE’d ._.
Azure Active Directory Flaw Allowed SAML Persistence
How Orca Found Server-Side Request Forgery (SSRF) Vulnerabilities in Four Different Azure Services
ACSESSED: Cross-tenant network bypass in Azure Cognitive Search