BTC$84,521-0.54% LTC$68.72+1.12% XMR$536.90-2.07%
TorPortal TorPortalMarkets, mirrors, dark web news

You are leaving TorPortal

The link you clicked points at a different website. We do not run that site and we cannot promise anything about what is on it. If you still want to go there, the button below opens it in a new tab.

ConfigConfusion: GCP IAM Authorization Bypass — Google Said 'Nice Catch' Then Left It Unpatched
olearysec.com

ConfigConfusion: GCP IAM Authorization Bypass — Google Said 'Nice Catch' Then Left It Unpatched

GCP IAM authorization bypass via Config Connector confused deputy allows any Kubernetes user to escalate to GCP Organization Owner, bypassing all IAM controls. CVSS 9.9. Google's VRP acknowledged it, then refused the bounty by miscategorizing it as a Config Connector issue instead of an IAM bypass.

Going to
olearysec.com
https://olearysec.com/research/config-connector-authorization-bypass/

If the address looks unfamiliar, close this tab and use the navigation above instead. TorPortal does not endorse third party sites and links inside news stories come straight from the source article.