services / Google Cloud / Dataproc clusters
Create and manage Dataproc clusters. Dataproc clusters provide a platform for running Apache Hadoop, Hive, Pig, and Spark jobs.
Allows access to machine-learning pipelines. Creating a cluster allows exfiltration of the default service account tokens.
dataproc.clusters.use
Allows the caller to submit a job to the cluster. Jobs may gain access to the cluster's short-lived service-account credentials.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog