Property
Languagehcl
Severitylow
CWECWE-284: Improper Access Control
OWASPA05:2017 - Broken Access Control
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The configuration grants public access to a Google Cloud Storage bucket by assigning the ‘allUsers’ member, making the bucket and its contents accessible to anyone on the internet. This exposes data without requiring authentication.

Impact#

If exploited, anyone can read, upload, or delete files in the affected storage bucket, leading to potential data leaks, unauthorized modifications, or loss of sensitive or critical information. This could result in privacy breaches, compliance violations, or service disruption.