AttachMe: critical OCI vulnerability allows unauthorized access to customer cloud storage volumes
ID: e4033710-a932-5b80-bbef-4754a4c9dcec
STIX ID: report--e4033710-a932-5b80-bbef-4754a4c9dcec
Feed Name: Wiz Blog
Threat Score
Wiz discovered and responsibly disclosed a critical OCI vulnerability named "AttachMe" that permitted cross-tenant attachment of block and boot volumes using only the volume OCID, enabling read/write access, data exfiltration, and potential code execution; Oracle patched the flaw within 24 hours and no customer action was required.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
