Property
Languagehcl
Severitylow
CWECWE-284: Improper Access Control
OWASPA05:2017 - Broken Access Control
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The Dataproc cluster IAM binding includes ‘allUsers’ or ‘allAuthenticatedUsers’ in the members list, which grants access to anyone on the internet or any authenticated Google user. This makes the cluster publicly or anonymously accessible, exposing sensitive resources.

Impact#

If exploited, unauthorized users could access, modify, or disrupt your Dataproc cluster, potentially leading to data leaks, resource misuse, or loss of control over your processing jobs. This can result in data breaches, increased costs, and regulatory violations.