jjjan / cloud-security-vulnerabilities

List of all the Publicly disclosed vulnerabilities of Public Cloud Provider like Amazon Web Services (AWS), Microsoft Azure, Google Cloud, Oracle Cloud, IBM Cloud etc

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Goal:

List of all the Publicly disclosed vulnerabilities of Public Cloud Provider like Amazon Web Services (AWS), Microsoft Azure, Google Cloud, Oracle Cloud, IBM Cloud etc

NOTE: This list will not cover any data breaches caused by misconfiguration

Table of contents

Contribute

Do you want to contribute to this list? Feel free to send a PR.

Cloud Service Provider Vulnerabilites

Amazon Web Services (AWS)

Microsoft Azure

Google Cloud

Oracle Cloud

IBM Cloud

All Cloud

  • sudo vulnerability - Published 6 August,2021 - Status: PARTIAL (requires User Caution)
  • Dynamic DNS - Published 6 August,2021 - Status: PARTIAL (requires User Caution)
  • Log4Shell - Published 13 December,2021 - Status: Resolved
  • Spring4Shell - Published 13 March,2022 - Status: Resolved

Useful Links

Security Bulletin

  • Amazon Web Services (AWS) - (link)
  • Microsoft - (link)
  • Google Cloud - (link)

Vulnerability Disclosure

All identified vulnerabilities should be disclosed to the vendors/maintainers of affected software or hardware systems directly. All major cloud providers have published disclosure addresses

Other Community Links - you may find helpful for Cloud Security

For more Cloud Security Resources, Training, Interviews and more check out Cloud Security Podcast Website | YouTube | Linkedin | Apple | Spotify | Twitter

About

List of all the Publicly disclosed vulnerabilities of Public Cloud Provider like Amazon Web Services (AWS), Microsoft Azure, Google Cloud, Oracle Cloud, IBM Cloud etc

License:Apache License 2.0