VDB

GCVE-110-CLOUD-2024-0031

GCVE-110-CLOUD-2024-0031
Advisory Published
Vulnetix · Advisory published June 17, 2024
GCP administrators face challenges in managing HMAC keys within their organizations, lacking visibility into which user accounts have generated these keys and whether they are actively being used to access storage objects. Additionally, there's a lack of functionality to revoke keys associated with other users, restricting their ability to enforce security policies effectively. Similarly, GCP incident response teams rely on Cloud Logging to monitor Cloud Storage object access, but they lack specific indicators to determine if HMAC keys are being utilized in these access attempts.

Affected Products

VendorProductVersionsPlatforms
GCPCloud Storage
GCPCloud Services
GCPGoogle Cloud Storage XML API, Google Cloud IAM

Browse GCVE Records

74,299 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›