HomeSecurityRCE vulnerability allows hackers to execute code on millions of servers

RCE vulnerability allows hackers to execute code on millions of servers

Security researchers have uncovered a serious remote code execution (RCE) vulnerability in Google Cloud Platform (GCP) , which may have allowed hackers to execute malicious code on millions of Google servers

RCE

The vulnerability, dubbed “CloudImposer” by Tenable Research, has now been patched by Google.

The vulnerability was discovered in GCP's Cloud Composer service, a managed workflow orchestration tool based on Apache Airflow. It stemmed from a dangerous package installation process that left the service exposed to dependency injection attacks.

Also read: Google expands the contact limit on the home screen widget

Tenable researchers discovered that Google was using the “–extra-index-url” argument when installing private Python in Cloud Composer. This argument tricks the package manager into checking both private and public repositories, which could allow hackers to trick it into installing malicious packages from public sources.

«The CloudImposer could have allowed attackers to launch massive attacks on the supply chain, endangering the Cloud Composer service of Google Cloud Platform for orchestrating software pipelines», said Liv Matan, security researcher at Tenable.

The vulnerability affected multiple GCP services, including App Engine, Cloud Functions, and Cloud Composer. By exploiting it, an attacker could upload a malicious package to the public PyPI, which would automatically install itself on elevated Cloud Composer instances. This could allow hackers to execute arbitrary code, steal credentials , and potentially move laterally to compromise other GCP services.

The widespread nature of the vulnerability meant that a single compromised package could impact millions of servers across Google’s infrastructure and customer environments. As Tenable noted, “supply chain attacks in the cloud are exponentially more damaging than on-premises. A malicious package in a cloud service can be deployed to – and cause harm to – millions of users.”

Google has now fixed the vulnerability, ensuring that the affected Python package is installed only from private repositories. The company has also implemented additional security measures, such as checksum verification, in order to ensure the integrity of the package.

See more: ConfusedFunction: Vulnerability discovered in Google Cloud

Responding to the findings, Google updated its documentation proposing the use of the more secure «–index-url» instead of «–extra-index-url» when installing packages. It also urges its customers to use the virtual Artifact Registry repository of GCP for managing multiple package sources.

The discovery highlights the ongoing challenges related to the security of cloud environments and software supply chains. It also highlights the need for cloud providers and customers to implement strict security practices around package management and dependency resolution.

Organizations that use GCP services are urged to review their package installation processes and ensure they have appropriate security safeguards to prevent attacks related to misinformation. This includes using version pinning, checksum checks, and private repositories where feasible.

google cloud RCE vulnerability

Read also: New cyber threats to Cloud systems and how to mitigate them

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The CloudImposer vulnerability reminds us of the complex and interconnected nature of modern cloud, and the potential for seemingly small misconfigurations to have far-reaching security implications. As cloud adoption continues to grow, addressing these risks in the supply chain will remain a critical priority for the sector.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS