services / Google Cloud / Cloud functions
Cloud functions is a serverless computing service. Functions are triggered in response to events and the code runs in an environment fully managed by Google.
cloudfunctions.functions.create
Creating a cloud function requires permissions on the cloud functions runtime service account. Includes a vulnerability where the user can export service account credentials, but exploiting this vulnerability requires the user to already have iam.serviceAccounts.actAs on the target service account.
Risks
Scope: CRITICAL
This privilege may grant access to sensitive data from a significant fraction of organizational functions, allow interruption of critical organizational services, or its exploit could lead to significant privilege escalation.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog