services / Google Cloud / Identity Aware Proxy web services resource type.

Refers to a particular IAP secured web service.

IAP is used to control access to cloud services. Changes to IAP related settings could remove access from mission-critical applications or grant an attacker access to sensitive resources.


iap.​webServices.​getSettings

Allows an attacker to read IAP related settings for this resource.

Risks

Scope: HIGH

This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.

Links

  • https:​/​/​cloud.​google.​com/​iap/​docs/​customizing
  • https:​/​/​cloud.​google.​com/​iap/​docs/​reference/​rest
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog