services / Google Cloud / BigQuery row-access policies

Row-level access policies for BigQuery tables.

Alteration of row-access policies can allow access to sensitive data or deny access to necessary data.


bigquery.​rowAccessPolicies.​getFilteredData

Should only be granted per row-access policy

Risks

Scope: HIGH

This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.

Links

  • https:​/​/​cloud.​google.​com/​bigquery/​docs/​row-​level-​security-​intro
  • https:​/​/​cloud.​google.​com/​bigquery/​docs/​access-​control
  • https:​/​/​cloud.​google.​com/​bigquery/​docs/​best-​practices-​row-​level-​security#​use_​the_​filtered_​data_​viewer_​role_​with_​caution
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog