Property
Languagehcl
Severitylow
CWECWE-284: Improper Access Control
OWASPA05:2017 - Broken Access Control
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

This code assigns a folder-level IAM role to a Google Cloud default service account. Default service accounts have broad permissions and are not intended for granular access control.

Impact#

If exploited, attackers or unauthorized users could abuse the over-privileged default service account to access or modify resources across all projects under the folder, increasing the risk of privilege escalation and data exposure.