Data protection

Storage bucket policy grant authenticated users object owner access

Risk Level

Informational (4)

Platform(s)
Compliance Frameworks

Description

Google Cloud Storage service allows you to store and retrieve data in a bucket. It was found that the {GcpStorageBucket} bucket is allowing Storage Legacy Bucket Object Owner permissions to all authenticated users. This could result with any authenticated user with a Google account executing object operations on the bucket.
  • Recommended Mitigation

    It is recommended to limit the bucket object owner access to authorized users only.