services / Google Cloud / Google App Engine services

A service is a logical component of an application that can share state and securely communicate with other services.

Application functionality relies on services: deleting or updating services can prevent normal application function.


appengine.​services.​get

Includes network discovery since it allows viewing of ingress traffic policies.

Risks

Scope: CRITICAL

This privilege may grant access to sensitive data from a significant fraction of organizational functions, allow interruption of critical organizational services, or its exploit could lead to significant privilege escalation.

Links

  • https:​/​/​cloud.​google.​com/​appengine/​docs/​admin-​api/​access-​control#​roles
  • https:​/​/​cloud.​google.​com/​appengine/​docs/​admin-​api/​reference/​rest/​v1/​apps.​services
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog