Property
Languagehcl
Severitylow
CWECWE-284: Improper Access Control
OWASPA05:2017 - Broken Access Control
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The code assigns IAM roles at the project level to Google Cloud’s default Compute Engine service account. Using default service accounts can grant excessive permissions and increase the risk of unintended access.

Impact#

If exploited, attackers or unauthorized users could leverage the default service account to access or modify resources across the project, potentially leading to data exposure, privilege escalation, or disruption of cloud services.