CVE-2023-27587
HIGH EXPLOITED NUCLEIreadtomyshoe < 2023-03-13 - Sensitive Information Exposure via Google Cloud TTS Error Message
Title source: llmExploitation Summary
CVE-2023-27587 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including vagnerd. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional PoC for CVE-2023-27587, demonstrating an information disclosure vulnerability in ReadToMyShoe where a Google Cloud API key is leaked in error messages. The PoC includes a curl command to trigger the vulnerability and a Nuclei template for automated detection.
Description
ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing sensitive information prior to commit 8533b01. If an error occurs when adding an article, the website shows the user an error message. If the error originates from the Google Cloud TTS request, then it will include the full URL of the request. The request URL contains the Google Cloud API key. This has been patched in commit 8533b01. Upgrading should be accompanied by deleting the current GCP API key and issuing a new one. There are no known workarounds.
Exploits (2)
This repository contains a functional PoC for CVE-2023-27587, demonstrating an information disclosure vulnerability in ReadToMyShoe where a Google Cloud API key is leaked in error messages. The PoC includes a curl command to trigger the vulnerability and a Nuclei template for automated detection.
This repository contains a functional PoC for CVE-2023-27587, demonstrating an information disclosure vulnerability in ReadToMyShoe where a Google Cloud API key is leaked in error messages. The PoC includes a curl command to trigger the vulnerability and a Nuclei template for detection.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N