GCP Cloud Composer Bug Let Attackers Elevate Access via Malicious PyPI Packages [email protected] (The Hacker News)

Cybersecurity researchers have detailed a now-patched vulnerability in Google Cloud Platform (GCP) that could have enabled an attacker to elevate their privileges in the Cloud Composer workflow orchestration service that’s based on Apache Airflow.
“This vulnerability lets attackers with edit permissions in Cloud Composer to escalate their access to the default Cloud Build service account, whichRead More 


Posted

in

by

Tags: