Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update the Vercel documentation #375

Merged
merged 1 commit into from
Jul 17, 2023
Merged

Update the Vercel documentation #375

merged 1 commit into from
Jul 17, 2023

Conversation

joren485
Copy link
Contributor

Description

Domain takeovers using Vercel are definitely still possible.

However, they are limited. In my testing, I found that a domain is not vulnerable if:

  • The root domain is used by a Vercel account (i.e. the root domain points to 76.76.21.21 and is linked to a project).
  • The domain/root domain is verified, even if the root domain does not point to 76.76.21.21.
  • Another subdomain of the same root domain is used by a Vercel account.

This PR updates the Vercel documentation to reflect this.

@EdOverflow EdOverflow merged commit cc212af into EdOverflow:master Jul 17, 2023
@EdOverflow
Copy link
Owner

Thank you, @joren485!

@zangcc
Copy link

zangcc commented Jun 6, 2024

Is this vulnerability no longer exploitable? Why hasn't the Status changed to Not vulnerable?

image

@EdOverflow @joren485

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants