Oracle Fixes Critical Bug in Cloud Code Editor
ID: f90c8a80-1401-5054-8c80-0ee59429d11c
STIX ID: report--f90c8a80-1401-5054-8c80-0ee59429d11c
Feed Name: Dark Reading
Tenable researchers found a critical remote-code-execution vulnerability in Oracle Cloud Infrastructure's Code Editor stemming from a missing CSRF check on a file upload router; because Code Editor and Cloud Shell share the same filesystem and session data, an attacker visiting a malicious webpage could upload a malicious file into a victim's Cloud Shell and leverage the victim's OCI permissions to access data or move laterally to Resource Manager, Functions, and Data Science. Oracle patched the issue by requiring a custom CSRF token header, closing the attack vector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
