Nir Ohfeld Profile picture
Cloud Vulnerability Researcher @wiz_io ✦
Dec 8, 2022 16 tweets 5 min read
We found a Remote Code Execution vulnerability in every #PostgreSQL database in #IBMCloud 😱

Here is how we did it: 🧵

#HellsKeychain We set up a PostgreSQL instance in IBM Cloud and tried to execute code using the 'COPY FROM PROGRAM' statement. Unfortunately, this failed due to insufficient privileges. We were blocked! 🚫