logo

Database

Gcp Public Buckets

Description

Detects Google Cloud Storage buckets that are configured to allow public access through IAM policies. Public buckets can expose sensitive data to unauthorized users and may violate security best practices that require explicit access controls.

Weakness:

325 - Excessive privileges - Wildcards

Category: Access Subversion

Detection Strategy

    Reports a vulnerability when a Cloud Storage bucket's public access prevention is not set to 'enforced'

    Reports a vulnerability when bucket IAM policies include members 'allUsers' or 'allAuthenticatedUsers'

    Each public access permission found in the bucket's IAM policy will generate a separate vulnerability report

Severity v4.0

1.7

Low

Method ID

CSPM-CKKRS

Technique

CSPM

Target

GCP

Technology

STORAGE

CWE ID(s)

CWE-250