Escalating Privileges in Google Cloud via Open Groups
netspi.com | 博客 | #bug-bounty | #cloud | #cloud-security | #privilege-escalation | #iam | #gcp | #google-groups
摘要
当 Google Group 被授予 GCP IAM 角色且加入权限设置为组织内任何人可加入时,普通成员可自行入组继承权限实现提权。NetSPI 通过 VRP 上报,Google 将其归类为 Won't Fix(预期行为),文章附带排查与检测思路。
- 发布时间
- 收录时间
Skip to content