services / Google Cloud / Compute Engine health checks

Create and manage legacy HTTP health checks used by Cloud load balancers.

Exploitation relies on multiple additional exercisable risks, including poorly secured backend endpoints, the ability to route to this infrastructure, and provisioned forwarding rules to the subject backends.


compute.​httpHealthChecks.​delete

May make backend infrastructure unroutable for intended uses.

Risks

Scope: HIGH

This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.

Links

  • https:​/​/​cloud.​google.​com/​load-​balancing/​docs/​health-​checks
  • https:​/​/​cloud.​google.​com/​sdk/​gcloud/​reference/​compute/​http-​health-​checks
  • https:​/​/​cloud.​google.​com/​compute/​docs/​reference/​rest/​v1/​httpHealthChecks
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog