National Cyber Warfare Foundation (NCWF)

GCP Cloud Composer Bug Let Attackers Elevate Access via Malicious PyPI Packages


0 user ratings
2025-04-22 14:28:24
milo
Blue Team (CND)
Cybersecurity researchers have detailed a now-patched vulnerability in Google Cloud Platform (GCP) that could have enabled an attacker to elevate their privileges in the Cloud Composer workflow orchestration service that's based on Apache Airflow.
"This vulnerability lets attackers with edit permissions in Cloud Composer to escalate their access to the default Cloud Build service account, which



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/04/gcp-cloud-composer-bug-let-attackers.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.