VDB
GCVE-110-CLOUD-2024-0031
GCVE-110-CLOUD-2024-0031
Advisory Published
GCP administrators face challenges in managing HMAC keys within their organizations,
lacking visibility into which user accounts have generated these keys and whether they are
actively being used to access storage objects. Additionally, there's a lack of functionality
to revoke keys associated with other users, restricting their ability to enforce security
policies effectively. Similarly, GCP incident response teams rely on Cloud Logging to monitor
Cloud Storage object access, but they lack specific indicators to determine if HMAC keys are
being utilized in these access attempts.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GCP | Cloud Storage | — | — |
| GCP | Cloud Services | — | — |
| GCP | Google Cloud Storage XML API, Google Cloud IAM | — | — |
Browse GCVE Records
74,299 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.