Back to directory
WRITEUP #155

Exploiting Broken Authentication Control In GraphQL

CloudGraphQLPrivilege escalation
by@ZatezaloAleksa(Aleksa Zatezalo)
Program
-
Published
Jul 24, 2024
Added to HackDex
Jul 30, 2024
Read Full Writeuphttps://www.praetorian.com/blog/exploiting-broken-authentication-control-graphql/
RELATED WRITEUPS
Addressed AWS defaults risks: OIDC, Terraform and Anonymous to AdministratorAccess
CloudOIDC
Double Agent: Exploiting Pass-through Authentication Credential Validation in Azure AD
CloudPrivilege escalation
UnOAuthorized: Privilege Elevation Through Microsoft Applications
CloudPrivilege escalation
Escalating Privileges in Google Cloud via Open Groups
CloudPrivilege escalation
ConfusedFunction: A Privilege Escalation Vulnerability Impacting GCP Cloud Functions
CloudPrivilege escalation

Built with ❤️ by Shubham Rawat