high

Privilege escalation on Dialogflow cloud platform

Published Sun, Jun 13th, 2021

Platforms

gcp

Summary

A privilege escalation vulnerability was discovered in Google's Dialogflow cloud platform. When downgrading a user's role from Developer to Reviewer, the permissions were not properly updated, allowing the user to retain Developer-level access. This issue persisted in the Google Cloud Console, where role changes resulted in additive permissions instead of replacements.

Affected Services

Dialogflow

Remediation

None required

Tracked CVEs

No tracked CVEs

References

Contributed by https://github.com/korniko98

Entry Status

Stub (AI-Generated)

Disclosure Date

Tue, Apr 6th, 2021

Exploitability Period

Until 2021/06/13

Known ITW Exploitation

-

Detection Methods

Administrators can verify user permissions in the Google Cloud Console IAM section to ensure they match the intended access levels set in Dialogflow.

Piercing Index Rating

-

Discovered by

lalka