writeups.xyz writeups.xyz / Cross-Tenant Vulnerability

Title Vulnerabilities Programs Authors
Lethal Injection: How We Hacked Microsoft's Healthcare Chat Bot
Arbitrary 1-click Azure tenant takeover via MS application
Wiz Research finds architecture risks that may compromise AI-as-a-Service providers and consequently risk customer data; works with Hugging Face on mitigations
Cross-Tenant Information Disclosure: Unraveling Microsoft Connections, Custom Connectors, and OAuth 2.0 in Power Automate
#BrokenSesame: Accidental ‘write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services
Two Minor Cross-Tenant Vulnerabilities in AWS App Runner
Riding the Azure Service Bus (Relay) into Power Platform
ACSESSED: Cross-tenant network bypass in Azure Cognitive Search
AttachMe: critical OCI vulnerability allows unauthorized access to customer cloud storage volumes
The cloud has an isolation problem: PostgreSQL vulnerabilities affect multiple cloud vendors
FabricScape: Escaping Service Fabric and Taking Over the Cluster
SynLapse – Technical Details for Critical Azure Synapse Vulnerability
Wiz Research discovers "ExtraReplica"— a cross-account database vulnerability in Azure PostgreSQL
AutoWarp: Critical Cross-Account Vulnerability in Microsoft Azure Automation Service
ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough
Cross-tenant Cloud Function compromise via storage bucket squatting