iTnews Asia
  • Home
  • News
  • Security

Google Cloud database service patched against critical vulnerability

Google Cloud database service patched against critical vulnerability

Attacker could get sysadmin on CloudSQL.

By Richard Chirgwin on May 29, 2023 11:44AM

A now-patched misconfiguration in Google Cloud Platform’s database service opened the possibility that an attacker could escalate their privilege to compromise other services.

Researchers at Dig Security found that the combination of a gap in GCP’s security layer for SQL Server, and a misconfiguration in the roles permission architecture, created a path by which they were able to create a user, and grant them sysadmin privileges.

The first allowed the researchers to create a user they could add to the GCP admin role “DbRootRole”.

“With the role `DbRootRole` we were able to do many things that we didn’t have permission to do before," the researchers wrote in a blog post describing the bug.

"Still, the `DbRootRole` is not a sysadmin role and doesn’t have full permissions on the SQL Server instance.”

Exploiting the second misconfiguration gave them “complete control on the database engine”, with the result that “our user was granted access to the operating system hosting the database."

"At this point we could access sensitive files in the host OS, list files and sensitive paths, read passwords, and extract secrets from the machine.”

Moreover, the post stated, “the host has access to the underlying service agents which could potentially lead to further escalation to other environments.”

Access to internal data such as secrets, URLs and passwords represented “a major security incident”, Dig Security said.

They also found that the breach gave them access to a Google internal Docker repository, which Google later blocked from external network access.

Dig Security first found the bug in early February, and Google Cloud identified the researchers’ activity and contacted them later that month.

Dig said Google Cloud fixed the bugs in April and awarded them a bug bounty.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
cloud cloudsql gcp google cloud platform security

Related Articles

  • How nations can forge their digital futures with Sovereign AI
  • Singapore’s construction firm Shingda Group centralises network operations
  • Five tips a CIO or CSO should know to stop employee-driven IP theft
  • StarHub launches app to protect customers from scam calls and SMS
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Five tips a CIO or CSO should know to stop employee-driven IP theft

Five tips a CIO or CSO should know to stop employee-driven IP theft

Beware the rise of ‘vishing’ as a cyber threat in APAC

Beware the rise of ‘vishing’ as a cyber threat in APAC

StarHub launches app to protect customers from scam calls and SMS

StarHub launches app to protect customers from scam calls and SMS

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.