VDB

GCVE-110-CLOUD-2020-0018

GCVE-110-CLOUD-2020-0018
Advisory Published
Vulnetix · Advisory published August 26, 2020
It was possible to list IAM service accounts of any GCP project, given only its ID, by forging a pageToken for the projects.serviceAccounts.list method of the IAM API. Due to the design of certain services in GCP, this issue could lead to exposure of sensitive information related to a project, and could be further used to enumerate unsecured resources in the platform, such as App Engine apps, Container Registry repositories, etc.

Affected Products

VendorProductVersionsPlatforms
GCPIAM, Projects
GCPCloud Services

Browse GCVE Records

77,901 records in the GCVE database · Updated August 9, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›