Write-ups
Check The Published Writeups
WDB | Title | Tags | Programs | Authors | Type | Publication | Added |
---|---|---|---|---|---|---|---|
2507 | XSS in the AWS Console | XSS CSP bypass CSTI | AWS | Nick Frichette (@frichette_n) | Bug Bounty | 2021-06-02 | 2023-06-13 |
797 | A Confused Deputy Vulnerability in AWS AppSync | Confused deputy Cloud Privilege escalation | AWS | Nick Frichette (@frichette_n) | Bug Bounty | 2022-11-21 | 2023-06-13 |
582 | AWS CloudTrail vulnerability: Undocumented API allows CloudTrail bypass | Cloud Logic flaw CloudTrail bypass | AWS | Nick Frichette (@frichette_n) | Bug Bounty | 2023-01-17 | 2023-06-13 |
278 | Bypassing CloudTrail in AWS Service Catalog, and Other Logging Research | Cloud CloudTrail bypass | AWS | Nick Frichette (@frichette_n) | Bug Bounty | 2023-03-20 | 2023-06-13 |
263 | Using an Undocumented Amplify API to Leak AWS Account IDs | Cloud Information disclosure | AWS | Nick Frichette (@frichette_n) | Bug Bounty | 2023-03-27 | 2023-06-13 |
236 | Two Minor Cross-Tenant Vulnerabilities in AWS App Runner | Cross-tenant vulnerability Cloud | AWS | Nick Frichette (@frichette_n) | Bug Bounty | 2023-04-03 | 2023-06-13 |