services / Google Cloud / Google Cloud SQL
A Cloud SQL instance is a VM managed by Google that runs the SQL database instance (as well as any accompanying containers)
Cloud SQL is used to store and serve sensitive and application-critical data. Breach of a cloud SQL database can lead to exfiltration of highly sensitive data, or interruption of mission-critical applications.
cloudsql.instances.rotateServerCa
Rotates the server certificate to one signed by the certificate authority version previously added. Can cause a denial of service if clients have not been updated to use the new certificate. There must be another certificate authority already added to exploit this.
Risks
Scope: CRITICAL
This privilege may grant access to sensitive data from a significant fraction of organizational functions, allow interruption of critical organizational services, or its exploit could lead to significant privilege escalation.
Links
Contributed by P0 Security