Collected research
Privilege Escalation in Google Cloud Platform’s Cloud Build
Shows that a principal with permission to create Cloud Build jobs can run an attacker-defined build and recover the default Cloud Build service account token. The technique turns a narrowly described build permission into the service account's often broader cloud privileges.
Record
- Researcher
- Spencer Gietzen
- Published by
- Rhino Security Labs
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Spencer Gietzen, first published at the original source. Preserved copies are kept so the citation survives its host.