VDB

GCVE-110-CLOUD-2022-0020

GCVE-110-CLOUD-2022-0020
Advisory Published
Vulnetix · Advisory published August 10, 2022
A vulnerability was discovered in Cloud Shell that enabled command injection and remote shell access. By manipulating the "project" parameter, an attacker could have cause an unencoded Python script execution flaw. Exploiting this flaw, they could inject a command to display the contents of the "/etc/passwd" file, successfully execute arbitrary commands and obtain remote shell access. However, the impact of this is unclear, as an attacker would seemingly only be able to gain such a remote shell on their own instance.

Affected Products

VendorProductVersionsPlatforms
GCPCloud Services
GCPGoogle Cloud Shell

References

advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›