Data protection

Storage bucket policy grant authenticated users object viewer access


Google Cloud Storage service allows you to store and retrieve data in a bucket. It was found that the {GcpStorageBucket} bucket is allowing Storage Legacy Bucket Object Admin permissions to all authenticated users. This could result with any authenticated user with a Google account viewing objects and their metadata in the bucket.