ConfusedComposer: A Privilege Escalation Vulnerability Impacting GCP Composer

Post Reply
Shane1145
Posts: 1729
Joined: Wed Sep 25, 2024 2:31 pm

ConfusedComposer: A Privilege Escalation Vulnerability Impacting GCP Composer

Post by Shane1145 »

Tenable Research discovered a privilege-escalation vulnerability in Google Cloud Platform (GCP) that is now fixed and which we dubbed ConfusedComposer. The vulnerability could have allowed an identity with permission (composer.environments.update) to edit a Cloud Composer environment to escalate privileges to the default Cloud Build service account. The default Cloud Build service account includes permissions to Cloud Build itself, as well as to Cloud Storage, Artifact Registry, and more.

https://securityboulevard.com/2025/04/c ... -composer/
Post Reply