services / Google Cloud / Compute Engine backend buckets
Cloud Storage buckets that may be referenced by load-balancer URL maps, or via Cloud CDN.
Generally used for providing publicly accessible data via a load balancer. This scope may depend on the exact configuration of the load balancer (e.g. if the load balancer requires certain cookies or auth tokens), and whether the load balancer itself is intended to be publicly accessible. The scope of read permissions should be downgraded to PUBLIC if only publicly accessible data are contained within these buckets.
compute.backendBuckets.addSignedUrlKey
Allows an attacker to forge signed URLs, potentially gaining access to additional data.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security