VDB

GCVE-110-CLOUD-2024-0016

GCVE-110-CLOUD-2024-0016
Advisory Published
Vulnetix · Advisory published September 16, 2024
Google Cloud Composer is a managed service for Apache Airflow. Tenable discovered that the Cloud Composer package was vulnerable to dependency confusion, which could have allowed attackers to inject malicious code when the package was compiled from source. This could have led to remote code execution on machines running Cloud Composer, which include various other GCP services as well as internal servers at Google. The dependency confusion stemmed from Google's risky recommendation in their documentation to use the --extra-index-url argument when installing private Python packages. Following disclosure, Google fixed the dependency confusion vulnerability and also updated their documentation.

Affected Products

VendorProductVersionsPlatforms
GCPCloud Services
GCPGoogle Cloud Composer, App Engine, Cloud Functions

References

CloudImposer
advisory
advisory

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›