Filling up the DagBag: Privilege Escalation in Google Cloud Composer
netspi.com | 漏洞 | #bug-bounty | #cloud | #cloud-security | #privilege-escalation | #gcp | #cloud-composer | #apache-airflow | #service-account
摘要
NetSPI 披露 Google Cloud Composer 提权路径:攻击者只需对环境的 Cloud Storage 存储桶有写权限,上传恶意 DAG 即可在 Airflow 中触发命令执行并接管绑定的服务账号;默认配置下该账号为项目级 Editor。Google VRP 将此判定为预期行为。
- 发布时间
- 收录时间
Skip to content