By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: GCP Cloud Composer Bug Let Attackers Elevate Access via Malicious PyPI Packages
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > GCP Cloud Composer Bug Let Attackers Elevate Access via Malicious PyPI Packages
Tech News

GCP Cloud Composer Bug Let Attackers Elevate Access via Malicious PyPI Packages

By Viral Trending Content 7 Min Read
Share
SHARE

Cybersecurity researchers have detailed a now-patched vulnerability in Google Cloud Platform (GCP) that could have enabled an attacker to elevate their privileges in the Cloud Composer workflow orchestration service that’s based on Apache Airflow.

“This vulnerability lets attackers with edit permissions in Cloud Composer to escalate their access to the default Cloud Build service account, which has high-level permissions across GCP services like Cloud Build itself, Cloud Storage, and Artifact Registry,” Liv Matan, senior security researcher at Tenable, said in a report shared with The Hacker News.

The shortcoming has been codenamed ConfusedComposer by the cybersecurity company, describing it as a variant of ConfusedFunction, a privilege escalation vulnerability impacting GCP’s Cloud Functions service that an attacker could exploit to access other services and sensitive data in an unauthorized manner.

The disclosure comes weeks after Tenable detailed another privilege escalation vulnerability in GCP Cloud Run dubbed ImageRunner that could have allowed a malicious actor to access container images and even inject malicious code — creating cascading effects.

Like ImageRunner, ConfusedComposer is another example of the Jenga concept, which causes security issues to be inherited from one service to the other when cloud service providers build new services atop existing ones.

Cybersecurity

The exploit hinges on the attacker having permission to edit a Cloud Composer environment (i.e., composer.environments.update), which could be exploited to inject a malicious Python Package Index (PyPI) package that’s capable of escalating privileges through Cloud Build.

The attack is made possible due to the fact that Cloud Composer allows users to install custom PyPI packages in their environments, thereby enabling an adversary to execute arbitrary code within the associated Cloud Build instance by using installation scripts inside their malicious package.

“ConfusedComposer is important because it exposes how behind-the-scenes interactions between cloud services can be exploited through privilege escalation,” Matan explained. “In this case, an attacker only needs permission to update a Cloud Composer environment to gain access to critical GCP services like Cloud Storage and Artifact Registry.”

Successful exploitation of the flaw could permit an attacker to siphon sensitive data, disrupt services, and deploy malicious code within CI/CD pipelines. Furthermore, it could pave the way for the deployment of backdoors that can grant persistent access to compromised cloud environments.

Following responsible disclosure by Tenable, Google has addressed the vulnerability as of April 13, 2025, by eliminating the use of the Cloud Build service account to install PyPI packages.

“The environment’s service account will be used instead,” Google said in an announcement on January 15, 2025. “Existing Cloud Composer 2 environments that previously used the default Cloud Build service account will change to using the environment’s service account instead.”

“Cloud Composer 2 environments created in versions 2.10.2 and later already have this change. Cloud Composer 3 environments already use the environment’s service account, and are not impacted by this change.”

The disclosure comes as Varonis Threat Labs uncovered a vulnerability in Microsoft Azure that could have allowed a threat actor with privileged access to an Azure SQL Server to alter configurations in a manner that causes data loss upon admin action. Microsoft has fully remediated the issue as of April 9, 2025, after it was made aware of it on August 5, 2024.

The Destructive Stored URL Parameter Injection vulnerability, the company said, stems from a lack of character limitation for server firewall rules created using Transact-SQL (T-SQL).

“By manipulating the name of server-level firewall rules through T-SQL, a threat actor with privileged access to an Azure SQL Server can inject an implant that, based on specific user actions, deletes arbitrary Azure resources that the user has permissions for,” security researcher Coby Abrams said.

“The impact of a threat actor exploiting this vulnerability could be large-scale data loss in the affected Azure account.”

It also comes as Datadog Security Labs shed light on a bug in Microsoft Entra ID restricted administrative units that could enable an attacker to prevent selected users from being modified, deleted, or disabled, even by a Global Administrator.

Cybersecurity

“A privileged attacker could have used this bug to protect an account under their control, preventing containment by any Entra ID administrator,” security researcher Katie Knowles said. This included various tasks such as resetting passwords, revoking user sessions, deleting users, and clearing user multi-factor authentication (MFA) methods.

The issue has since been fixed by the Windows maker as of February 22, 2025, following responsible disclosure on August 19, 2024.

In recent weeks, threat actors have been found training their sights on websites hosted on Amazon Web Services (AWS) Elastic Compute Cloud (EC2) instances by exploiting Server-Side Request Forgery (SSRF) vulnerabilities to extract metadata information.

“EC2 Instance Metadata is a feature provided by AWS that allows an EC2 instance to access information needed at runtime without needing to authenticate or make external API calls,” F5 Labs researcher Merlyn Albery-Speyer said. “It can expose information such as the public or private IP address, instance ID, and IAM role credentials. Much of this is sensitive data of interest to attackers.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

The Best Earplugs for Protecting Your Hearing (2026)

The X-Files Reboot Potential Release Date, Cast, Plot And News

AirPods Max 2: Apple’s Over-Ear Redemption is Finally Here

China’s DeepSeek suffers rare outage lasting several hours

Best Fitness Tracker 2026: Fitbits, Bands & Hybrids

TAGGED: Cloud security, Cyber Security, Cybersecurity, Google Cloud Platform, Internet, Microsoft Azure, privilege escalation, PyPI, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article New SEC chair Paul Atkins begins term as 72 crypto ETFs await approval
Next Article Tata Communications Q4 Results: Profit rises 15% to Rs 336 crore on data services demand
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

The Best Earplugs for Protecting Your Hearing (2026)
Tech News
Cvancara upgrade: Celtic earmark 15-goal English striker as summer target
Sports
Why Coal India's arm CMPDI could be a buy even after 7% IPO debut crash today
Business
Solana price drops as BTC, ETH slip amid oil surge to $110
Crypto
Investors are rushing to buy these before the Stocks and Shares ISA deadline. Should we join in?
Business
The X-Files Reboot Potential Release Date, Cast, Plot And News
Tech News
The Houston Comets are back: Connecticut Sun sold to Rockets owner for record $300 million
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

The Best Earplugs for Protecting Your Hearing (2026)

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
The Best Earplugs for Protecting Your Hearing (2026)
March 30, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?