Vendor services misconfigurations

Cloud function with policy members ‘all authenticated users’

Platform(s)
Compliance Frameworks

CCPA, CPRA, iso_27001_2022, iso_27002_2022, Mitre ATT&CK, NIST 800-171, NIST 800-53, Orca Best Practices, PDPA, UK Cyber Essentials

Description

GCP cloud function {GcpCloudFunction} was detected running with policy bindings with 'allAuthenticatedUsers' in Members, allowing access to all authenticated users with a Google account.