services / Google Cloud / Cloud Storage buckets
Buckets are the basic unit of data storage within Cloud Storage. All data must be contained in a bucket.
Buckets may be used to store data of various sensitivities, from publicly available data to very sensitive confidential data.
storage.buckets.deleteTagBinding
A common use case of tag bindings is for use in IAM policy conditions. The "destruction:policy" and "impact:access" risks apply if the tag is used in any policies.
Risks
Scope: CRITICAL
This privilege may grant access to sensitive data from a significant fraction of organizational functions, allow interruption of critical organizational services, or its exploit could lead to significant privilege escalation.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog