gcp-pd-disk-filesystem-content

Attaching a disk read-only or restoring/exporting a snapshot exposes every plaintext secret stored in its filesystem.

gcpcritical service: gcp:pd emits CanReadData

Where it sits

locationCompute Engine disk attachment or snapshot export.mounted filesystem bytes
location kinddata_record
data kindscredential private_key source_code_secret customer_data pii
emits edgeCanReadData
servicePersistent Disk / Snapshots (gcp:pd)

Collection recipe

access modedata_plane
operationCompute Engine disk attachment or snapshot export
response pathmounted filesystem bytes
encodingbinary
params{"name": "\u003cresource-name\u003e"}

Required permissions

compute.disks.useReadOnly
compute.instances.attachDisk

References

move · open · esc close