No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Google Cloud Build Flaw Enables Privilege Escalation, Code Tampering

July 19, 2023
in Protection
0
Google Cloud Build Flaw Enables Privilege Escalation, Code Tampering



A newly discovered vulnerability in Google Cloud Build enables attackers to tamper with and inject malware into images stored in Artifact Registry, Google’s repository for hosting software artifacts such as packages and container images.

Any applications then making use of those compromised container images risk malware infections, denial-of-service attacks, data theft, and other negative impacts.

The Bad.Build Issue

Researchers at Orca Security recently discovered the flaw, which they dubbed Bad.Build, when analyzing an application programming interface (API) call request associated with a Google cloud platform resource. They reported the issue to Google, which investigated the problem and issued a fix for it in June.

However, Orca, in a report this week, described the fix as insufficient and only partially addressing the vulnerability.

“The flaw presents a significant supply chain risk since it allows attackers to maliciously tamper with application images, which can then infect users and customers when they install the application,” Orca cloud threat researcher Roi Nisimi said. “As we have seen with the SolarWinds and recent 3CX and MOVEit supply chain attacks, this can have far reaching consequences.”

According to Orca, the Bad.Build flaw really is a design issue and has to do with the default permissions associated with the Google Cloud Build service. The excessive permissions associated with the service give adversaries a relatively easy way to access audit logs that contain a complete list of permissions associated with all GCP accounts in a Google Cloud Build “Project.”

“What makes this information so lucrative is that it greatly facilitates lateral movement and privilege escalation in the environment,” Nisimi said. “Knowing which GCP account can perform which action is equal to solving a great piece of the puzzle on how to launch an attack.”

Orca’s researchers discovered that by using a GCP account with the permission to create a new build (cloudbuild.builds.create), they could relatively easily impersonate the Cloud Build Service account and view all Project permissions. “An attacker would need to have access to the cloudbuild.builds.create permission, which could either be obtained through insider access or by an outsider that has gained unauthorized access to a user with this permission,” says Nisimi, in comments to Dark Reading.

Simple to Exploit

“They would need to execute just three lines of code to build a public Gcloud image on the Cloud Build servers and run the commands as shown in our proof of concept to escalate the user’s privileges and execute any action that the Cloud Build Service Account is allowed to perform,” he says.

Google’s fix for Bad.Build removes the logging permission from the default Google Cloud Build service role, which means that particular service no longer has access to the audit logs which list the entire Project’s permissions each time there’s a change, Nisimi notes.

However, there is a whole list of other roles with the cloudbuild.builds.create permission that can do the same thing. Any user with the cloudbuild.builds.create permission can escalate privileges and execute a wide range of actions — including manipulating images and injecting malicious code into them — unless organizations specifically revoke the default permissions of the Google Cloud Build service, he says.

A Google spokeswoman had little to say about the flaw or the claims of a partial fix. “We appreciate the work of the researchers and have incorporated a fix based on their report as outlined in a security bulletin issued in early June,” she said.

Limiting Privileges

When users enable the Cloud Build API in a project, Cloud Build automatically creates a default service account to execute builds on the user’s behalf, according to Google’s advisory on the vulnerability. This Cloud Build service account previously allowed the build to have access to private logs by default, but as the June 8 security bulletin noted, “This permission has now been revoked from the Cloud Build service account to adhere to the security principle of least privilege.”

According to Nisimi, Google’s stance appears to be that the issue is the default permissions that organizations choose to enable for Cloud Build. He says, “Google recognizes that there is a supply-chain attack risk as described, but that it revolves around the choice of default permissions supporting the most common development workflows.”

Google’s stance is that customers are responsible for further locking down access for more advanced scenarios. “Therefore the supply chain risk is persistent, and organizations must limit the cloudbuild.builds.create permission as much as possible to reduce the risk of a supply chain attack,” Nisimi says.

Editorial Team

Editorial Team

Related Posts

My Three Favorite Garmin Features to Use on Race Day
Protection

My Three Favorite Garmin Features to Use on Race Day

May 5, 2026
You Might Get Some Money From This PlayStation Store Lawsuit
Protection

You Might Get Some Money From This PlayStation Store Lawsuit

May 4, 2026
10 Hacks Every Apple Notes User Should Know
Protection

10 Hacks Every Apple Notes User Should Know

May 4, 2026
The Top Ten Movies Streaming Now
Protection

The Top Ten Movies Streaming Now

May 4, 2026
You Can Already Save $80 on the New M4 iPad Air
Protection

You Can Already Save $80 on the New M4 iPad Air

May 4, 2026
The New AirPods Max 2 Are $40 Off Right Now
Protection

The New AirPods Max 2 Are $40 Off Right Now

May 4, 2026
Load More
Next Post
Fed's last rate hike coming at July meeting, economists say

Fed's last rate hike coming at July meeting, economists say

Popular News

  • Monarch is a budgeting app that makes it easy for couples to track shared expenses, create flexible budgets, and set joint financial goals — all without spreadsheets. Here's what it was like to use it for a month.

    I Used Monarch Money for 30 Days: Here’s What Happened

    0 shares
    Share 0 Tweet 0
  • 5 Things to Know About the Neu Credit Card

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • US Crypto Bill Moves Closer To Approval After Stablecoin Yield Text Unveiled

    0 shares
    Share 0 Tweet 0
  • What The Sharp Drop In The Coinbase Bitcoin Premium Means For The BTC Price

    0 shares
    Share 0 Tweet 0

Latest News

Cointelegraph

Haun Ventures Raises $1B to Fund Crypto, AI Startups

May 5, 2026
0

Haun Ventures has raised $1 billion to back early- and late-stage crypto startups, while expanding into artificial intelligence for the...

How beleaguered are beer sales? Anheuser-Busch InBev volumes rose 1% and the stock market is delighted

How beleaguered are beer sales? Anheuser-Busch InBev volumes rose 1% and the stock market is delighted

May 5, 2026
0

Anheuser-Busch InBev shares surged on Tuesday as the brewer of Budweiser, Corona and Michelob reported volume growth of 0.8% in...

Coinbase opens crypto access for Australia’s self-managed retirement funds - 1

Coinbase opens crypto access for Australia’s self-managed retirement funds

May 5, 2026
0

Coinbase Australia has launched support for self-managed super funds, giving trustees a new way to add crypto exposure to retirement...

Hong Kong Q1 GDP expands at strongest pace in nearly five years

Hong Kong Q1 GDP expands at strongest pace in nearly five years

May 5, 2026
0

Hong Kong Q1 GDP expands at strongest pace in nearly five years

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.