VDB
GCVE-110-CLOUD-2020-0018
GCVE-110-CLOUD-2020-0018
Advisory Published
It was possible to list IAM service accounts of any GCP project, given only its ID, by forging a pageToken for the projects.serviceAccounts.list
method of the IAM API. Due to the design of certain services in GCP, this issue could lead to exposure of sensitive information related to a project,
and could be further used to enumerate unsecured resources in the platform, such as App Engine apps, Container Registry repositories, etc.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GCP | IAM, Projects | — | — |
| GCP | Cloud Services | — | — |
Browse GCVE Records
77,901 records in the GCVE database · Updated August 9, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.