Property
Languagehcl
Severitylow
CWECWE-284: Improper Access Control
OWASPA05:2017 - Broken Access Control
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

Assigning the ‘roles/editor’ permission at the organization level in GCP allows users to manage all resources, including impersonating and managing all service accounts. This grants overly broad privileges that can lead to unauthorized actions.

Impact#

If exploited, an attacker or unauthorized user could gain full control over resources and service accounts across the entire organization. This could allow them to access sensitive data, escalate privileges, or disrupt organizational operations.