Several internal applications have open CORS, allowing external folks to access the content

Disclosed by
bigBugGuy's avatar
bigBugGuy
  • Engagement Tesla
  • Disclosed date over 2 years ago
  • Points 20
  • Priority P2 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by Tesla

Allowing disclosure with limited visibility since the report contains information about internal hosts

Summary by bigBugGuy

Using a typosquat domain, I was able to get access to a browser that sat on an internal Tesla network, without social engineering anyone. From there, I could access all the open CORs domains:

aads.teslamotors.com 
envoy-commerce.teslamotors.com 
packaging-v2-api-stg.teslamotors.com 
packaging-v2-api.teslamotors.com 
location.teslamotors.com 
messagecenter-external-api-stage.teslamotors.com 
m3location.teslamotors.com 
payment-gateway.teslamotors.com 
onboarding-pre-delivery-prod.teslamotors.com 
eaa-setup.teslamotors.com

That response data was then sent back out to me. The team was quick to triage the issue, and fix the permissive CORs issue.

Activity
  1. Nick’s avatar
    Nick Customer sent a message

    ()

  2. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  3. Nick’s avatar
    Nick Customer sent a message

    ()

  4. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  5. Nick’s avatar
    Nick Customer sent a message

    ()

  6. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  7. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  8. Nick’s avatar
    Nick Customer sent a message

    ()

  9. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  10. Nick’s avatar
    Nick Customer sent a message

    ()

  11. Nick’s avatar
    Nick Customer published the disclosure report

    ()

  12. Nick’s avatar
    Nick Customer sent a message

    ()

  13. Nick’s avatar
    Nick Customer changed the state to Resolved

    ()

  14. bigBugGuy’s avatar
    bigBugGuy requested disclosure

    ()

  15. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  16. Nick’s avatar
    Nick Customer sent a message

    ()

  17. Nick’s avatar
    Nick Customer changed the severity to P2

    ()

  18. Nick’s avatar
    Nick Customer rewarded bigBugGuy 15 points

    ()

  19. Nick’s avatar
    Nick Customer rewarded bigBugGuy

    ()

  20. Nick’s avatar
    Nick Customer changed the state to Unresolved

    ()

  21. Nick’s avatar
    Nick Customer rewarded bigBugGuy 5 points

    ()

  22. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  23. bigBugGuy’s avatar
    bigBugGuy sent a message

    ()

  24. Nick’s avatar
    Nick Customer changed the state to Triaged

    ()

  25. Nick’s avatar
    Nick Customer sent a message

    ()

  26. bigBugGuy’s avatar
    bigBugGuy created the submission

    ()