Published Sun, Jun 13th, 2021
Platforms
A privilege escalation vulnerability was discovered in Google's Dialogflow cloud platform. When downgrading a user's role from Developer to Reviewer, the permissions were not properly updated, allowing the user to retain Developer-level access. This issue persisted in the Google Cloud Console, where role changes resulted in additive permissions instead of replacements.
Dialogflow
None required
No tracked CVEs
Contributed by https://github.com/korniko98
Entry Status
Stub (AI-Generated)
Disclosure Date
Tue, Apr 6th, 2021
Exploitability Period
Until 2021/06/13
Known ITW Exploitation
-
Detection Methods
Administrators can verify user permissions in the Google Cloud Console IAM section to ensure they match the intended access levels set in Dialogflow.
Piercing Index Rating
-
Discovered by
lalka