logo

Database

Gcp Lifecycle Not Defined

Description

Detects Google Cloud Storage buckets that do not have lifecycle management rules defined. Missing lifecycle rules can lead to unnecessary storage costs and security risks as old or unused data is not automatically cleaned up or transitioned to appropriate storage classes.

Weakness:

200 - Traceability loss

Category: Functionality Abuse

Detection Strategy

    Scans all Cloud Storage buckets in the GCP project

    Checks if each bucket has any lifecycle rules configured in its properties

    Reports a vulnerability if a bucket's lifecycle_rules list is empty

    Includes the bucket path and project ID in the vulnerability report for identification

Severity v4.0

0.5

Low

Method ID

CSPM-E0TIO

Technique

CSPM

Target

GCP

Technology

STORAGE

CWE ID(s)

CWE-778