Tech

Google Toldl Researchers ‘Nice Catch!’ Then Denied Bug Bounty For Flaw It Still Hasn’t Fixed

Published

on

Security researcher Justin O’Leary says Google initially accepted his Config Connector privilege-escalation report as a high-priority, high-severity bug, then denied a bounty by declaring the behavior “working as intended.” “Google initially rated the bug high priority and high severity, with a rep telling O’Leary ‘Nice Catch!’ Then, the cloud giant changed course and told O’Leary […] that there’s no vulnerability, so no fix and no reward payout,” reports The Register. “The bug report, however, is still marked high-priority and accepted.” The alleged flaw, dubbed ConfigConfusion, could let a Kubernetes namespace user exploit an overprivileged service account to become a GCP organization owner with only a few lines of YAML and little apparent audit visibility. O’Leary details the incident in a blog post. The Register reports: According to O’Leary, Config Connector doesn’t perform an authorization check, and this allows any Config Connector service account with org-level permissions to bypass Identity and Access Management (IAM) authorization and gain the highest level of control (roles/owner) to an entire GCP Organization — the root node of all of a company’s resources within Google Cloud. On March 27, a Google security engineer accepted O’Leary’s report and told him: “Nice catch!” The employee said that they filed a bug based on O’Leary’s report with the relevant product team and assured him the Chocolate Factory’s security squad would work with relevant Google Cloud people to fix the flaw. “We’ll work with the product team to ensure this issue is address. We’ll let you know when the issue was fixed,” the engineer said. “In the meantime, review the payment option selected in your bughunters.google.com profile.”

Google assigned the bug P1 priority and S1 severity, signifying a flaw worthy of urgent repair because it affects a large percentage of users and can disrupt core organizational functions. “I figured that was the end of that,” O’Leary said in a phone interview with The Register. Eleven days later, on April 7, he received a new message from a Google Security Bot reversing the earlier decision. The Reg viewed the email, and O’Leary included a screenshot in his Thursday writeup. The message said that the Cloud Vulnerability Reward Program panel decided that the “security impact of this issue does not meet the criteria to qualify for a reward.”

After reviewing the bug report, Google determined the software “is working as intended,” the message continued. It also noted that the program’s decision not to pay a bounty “does not mean that the product team won’t fix the issue.” Nearly three months later, the case remains P1/S1 with the status “in progress (accepted).” Google hasn’t assigned a CVE or issued a fix. O’Leary didn’t receive any reward for his research. […] “This is a pattern,” O’Leary told [The Register]. “This is just how these trillion-dollar companies deal with people like me. In my day job, we use GKE, and it’s incredibly frustrating on my end, when I find a critical vulnerability in the system that’s being widely used, and I can’t even get the vendor to patch their own stuff.” A Google spokesperson told The Register: “The issue reported does not qualify for a reward because the GCP IAM authorization bypass is only exploitable if an attacker has access to a Config Connector Service Account that’s been granted the Organization Admin role by the organization (i.e., it is privileged). Additionally, an attacker would first need to gain entry to an organization’s environment (e.g., an exposed container) in order to leverage the privileged Config Connector instance and execute commands with administrative authority, such as the IAM bypass. Granting this level of access to the Config Connector Service Account goes against Google Cloud’s publicly shared best practices and the principle of least privilege.”

Source link

Advertisement

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version