<?xml version="1.0" encoding="UTF-8"?>

<!-- AUTOGENERATED FILE. DO NOT EDIT. -->

<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:cloud-build-security-bulletins</id>
  <title>Cloud Build - Security Bulletins</title>
  <link rel="self" href="https://cloud.google.com/feeds/cloud-build-security-bulletins.xml"/>
  <author>
    <name>Google Cloud</name>
  </author>
  <updated>2023-06-08T15:31:34.335656+00:00</updated>


  <entry>
    <title>GCP-2023-013</title>
    <id>tag:google.com,2016:cloud-build-security-bulletins#GCP-2023-013</id>
    <updated>2023-06-08T00:00:00+00:00</updated>
    <link rel="alternate" href="https://cloud.google.com/build/docs/security-bulletins#GCP-2023-013"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2023-06-08</p><h3 class="hide-from-toc" data-text="Description" id="description">Description</h3><table>
<thead>
<tr>
<th>Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td><p>When you enable the Cloud Build API in a project, Cloud Build automatically creates a <a href="https://cloud.google.com/build/docs/cloud-build-service-account">default service account</a> to execute builds on your behalf. This Cloud Build service account previously had the <code dir="ltr" translate="no">logging.privateLogEntries.list</code> IAM permission, which allowed the build to have access to list private logs by default. This permission has now been revoked from the Cloud Build service account to adhere to the <a href="https://cloud.google.com/iam/docs/using-iam-securely#least_privilege">security principle of least privilege</a>.</p> <p><b>What should I do?</b></p> <p>No further user action is required. The <code dir="ltr" translate="no">logging.privateLogEntries.list</code> IAM permission has been revoked from the Cloud Build service account and the fix has been rolled out.</p> <p><b>What vulnerabilities are addressed by this patch?</b></p> <p>This vulnerability granted builds the permission to access private logs. Since the <code dir="ltr" translate="no">logging.privateLogEntries.list</code> IAM permission has now been revoked from the Cloud Build service account, builds no longer have access to list private logs by default.</p></td>
<td>Low</td>
<td></td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>


</feed>
