By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Google Fixes GCP Composer Flaw That Could’ve Led to Remote Code Execution
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Google Fixes GCP Composer Flaw That Could’ve Led to Remote Code Execution
Tech News

Google Fixes GCP Composer Flaw That Could’ve Led to Remote Code Execution

By Viral Trending Content 4 Min Read
Share
SHARE

Sep 16, 2024Ravie LakshmananCloud Security / Vulnerability

Google Fixes GCP Composer Flaw

A now-patched critical security flaw impacting Google Cloud Platform (GCP) Composer could have been exploited to achieve remote code execution on cloud servers by means of a supply chain attack technique called dependency confusion.

The vulnerability has been codenamed CloudImposer by Tenable Research.

“The vulnerability could have allowed an attacker to hijack an internal software dependency that Google pre-installs on each Google Cloud Composer pipeline-orchestration tool,” security researcher Liv Matan said in a report shared with The Hacker News.

Dependency confusion (aka substitution attack), which was first documented by security researcher Alex Birsan in February 2021, refers to a type of software supply chain compromise in which a package manager is tricked into pulling a malicious package from a public repository instead of the intended file of the same name from an internal repository.

Cybersecurity

So, a threat actor could stage a large-scale supply chain attack by publishing a counterfeit package to a public package repository with the same name as a package internally developed by companies and with a higher version number.

This, in turn, causes the package manager to unknowingly download the malicious package from the public repository instead of the private repository, effectively replacing the existing package dependency with its rogue counterpart.

The problem identified by Tenable is similar in that it could be abused to upload a malicious package to the Python Package Index (PyPI) repository with the name “google-cloud-datacatalog-lineage-producer-client,” which could then be preinstalled on all Composer instances with elevated permissions.

While Cloud Composer requires that the package in question is version-pinned (i.e., version 0.1.0), Tenable found that using the “–extra-index-url” argument during a “pip install” command prioritizes fetching the package from the public registry, thereby opening the door to dependency confusion.

Armed with this privilege, attackers could execute code, exfiltrate service account credentials, and move laterally in the victim’s environment to other GCP services.

Following responsible disclosure on January 18, 2024, it was fixed by Google in May 2024 by ensuring that the package is only installed from a private repository. It has also added the extra precaution of verifying the package’s checksum in order to confirm its integrity and validate that it has not been tampered with.

The Python Packaging Authority (PyPA) is said to have been aware of the risks posed by the “–extra-index-url” argument since at least March 2018, urging users to skip using PyPI in cases where the internal package needs to be pulled.

Cybersecurity

“Packages are expected to be unique up to name and version, so two wheels with the same package name and version are treated as indistinguishable by pip,” a PyPA member noted at the time. “This is a deliberate feature of the package metadata, and not likely to change.”

Google, as part of its fix, now also recommends that developers use the “–index-url” argument instead of the “–extra-index-url” argument and that GCP customers make use of an Artifact Registry virtual repository when requiring multiple repositories.

“The ‘–index-url’ argument reduces the risk of dependency confusion attacks by only searching for packages in the registry that was defined as a given value for that argument,” Matan said.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Europe’s public sector deploying AI faster than it can manage – report

The Best Outdoor Deals From the REI Anniversary Sale 2026

New ‘Pack2TheRoot’ flaw gives hackers root Linux access

Google Pixel Phone eSIM Bug Widely Reported

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

TAGGED: Cloud security, Cyber Security, Dependency Confusion, Google Cloud Platform, Internet, Python, Remote Code Execution, software security, supply chain attack, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Unlock Massive Gains: 3 Reasons to Add FLOKI & GEGG to Your Portfolio as They Shake the Market
Next Article BitGo launches a digital asset management platform for protocols
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Berkshire triples Alphabet stake and buys Delta stock while dumping Amazon in Greg Abel’s first quarter as CEO
Business
Solayer launches Visa-compatible card for USDC payments
Crypto
A call to stop the global housing: World Urban Forum, why it matters?
World News
ZachXBT Claims LAB Insiders Control 95% After $6 Billion Crypto Pump
Crypto
007 First Light’s James Bond Actor Was “Pretty Stunned” to Learn Of His Casting
Gaming News
American Express Expands Centurion Lounge Network
Travel
Spain’s place in global politeness and manners ranking raises eyebrows
World News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Berkshire triples Alphabet stake and buys Delta stock while dumping Amazon in Greg Abel’s first quarter as CEO

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Berkshire triples Alphabet stake and buys Delta stock while dumping Amazon in Greg Abel’s first quarter as CEO
May 16, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?