Filling up the DagBag: Privilege Escalation in Google Cloud Composer
netspi.com | vulnerability | #bug-bounty | #cloud | #cloud-security | #privilege-escalation | #gcp | #cloud-composer | #apache-airflow | #service-account
Summary
Write access to a Cloud Composer storage bucket lets attackers upload a malicious DAG, gain command execution, and hijack its service account, which defaults to project Editor privileges.
- Published
- Collected
Skip to content