Source |
The Hacker News |
Identifiant |
8339647 |
Date de publication |
2023-05-26 21:55:00 (vue: 2023-05-26 17:06:56) |
Titre |
Flaw sévère dans le service SQL Cloud de Google Cloud \\ Severe Flaw in Google Cloud\\'s Cloud SQL Service Exposed Confidential Data |
Texte |
Un nouveau défaut de sécurité a été divulgué dans le service SQL cloud de Google Cloud Platform \\) qui pourrait être exploité pour obtenir l'accès à des données confidentielles.
"La vulnérabilité aurait pu permettre à un acteur malveillant de passer d'un utilisateur SQL Cloud de base à un système à part
A new security flaw has been disclosed in the Google Cloud Platform\'s (GCP) Cloud SQL service that could be potentially exploited to obtain access to confidential data.
"The vulnerability could have enabled a malicious actor to escalate from a basic Cloud SQL user to a full-fledged sysadmin on a container, gaining access to internal GCP data like secrets, sensitive files, passwords, in addition |
Notes |
★★
|
Envoyé |
Oui |
Condensat |
access actor addition basic been cloud confidential container could data disclosed enabled escalate exploited exposed files flaw fledged from full gaining gcp google has have internal like malicious new obtain passwords platform potentially secrets security sensitive service severe sql sysadmin user vulnerability |
Tags |
Vulnerability
Cloud
|
Stories |
|
Move |
|