Slide 41
Slide 41 text
Full timeline
Reference: https://jdomeracki.github.io/2024/11/09/sketchy_cheat_sheet/#full-timeline
Nov 22, 2023: Initial submission of issu.ee/312687013
Nov 22, 2023: Status: Won't Fix (Not Reproducible)
Nov 23, 2023: Clarification + full PoC
Nov 23, 2023: 🎉 Nice catch! (P2,S2)
Nov 28, 2023: Submitted report on the misconfigured Firebase Cloud Storage bucket allowing read & write operations issu.ee/313685590
Nov 30, 2023: 🎉 Nice catch! (P2,S2)
Dec 27, 2023: issu.ee/313685590 status changed to fixed
Mar 16, 2024: Found out that the bucket is still publicly readable & writable
Mar 20, 2024: issu.ee/313685590 got reopened & assigned
Mar 28, 2024: VRP Panel decided not to reward monetarily for the second time, but got a coupon for a cool hat instead
Apr 06, 2024: Reported a bypass of the mitigation introduced somewhen in Q1 2024 and submitted a new report issu.ee/333194226
Apr 10, 2024: 🎉 Nice catch! (P2,S2)
Jun 15, 2024: Ability to overwrite deployable architectures opens room for RCE in victim's GCP infrastructure issu.ee/347462501
Jun 26, 2024: 🎉 Nice catch! (P2,S2)
Jun 26, 2024: Reported anonymous access to a Gerrit instance containing the backend source code issu.ee/349432799
Jun 27, 2024: Unauthorized access to a GCS bucket containing Terraform artifacts via a misconfigured Cloud Function issu.ee/349831037
Jun 27, 2024: 🎉 Nice catch! (P1,S1)
Jul 02, 2024: 🎉 Nice catch! (P2,S2)
Jul 03, 2024: https://googlecloudcheatsheet.withgoogle.com/architecture got taken down 🚧