medium

Bucket Traversal in Google Cloud Storage Transfer Manager

Published Tue, Jun 13th, 2023

Platforms

gcp

Summary

A bucket traversal vulnerability was discovered in the google.cloud.storage.transfer_manager.upload_chunks_concurrently() function of Google Cloud Storage. This issue could potentially allow unauthorized access to files in different buckets or directories within the same project.

Affected Services

Cloud Storage

Remediation

None required

Tracked CVEs

No tracked CVEs

References

Contributed by https://github.com/korniko98

Entry Status

Stub (AI-Generated)

Disclosure Date

-

Exploitability Period

-

Known ITW Exploitation

-

Detection Methods

Monitor access logs for suspicious file access patterns across different buckets or directories within Google Cloud Storage projects.

Piercing Index Rating

-

Discovered by

Google Bug Hunters