Property
Languagehcl
Severitylow
CWECWE-320: CWE CATEGORY: Key Management Errors
OWASPA03:2017 - Sensitive Data Exposure
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The Vertex AI Metadata Store resource is not configured to use a customer-managed encryption key (CMK) for its data. This means sensitive metadata may be encrypted only with default Google-managed keys, reducing control over data security.

Impact#

Without a CMK, your organization cannot control or revoke encryption keys, making it harder to manage access to sensitive information. If Google’s default keys are compromised or subpoenaed, attackers or unauthorized parties could potentially access confidential metadata stored in Vertex AI.