Property
Languagehcl
Severitylow
CWECWE-284: Improper Access Control
OWASPA05:2017 - Broken Access Control
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The code assigns ‘allUsers’ or ‘allAuthenticatedUsers’ as members to a Google Pub/Sub topic, making it accessible to anyone on the internet or any authenticated user. This configuration exposes the topic to unauthorized access.

Impact#

If exploited, anyone could publish or subscribe to the Pub/Sub topic, potentially leading to data leaks, unauthorized message injection, or service abuse. This can compromise sensitive information and disrupt application workflows.