Tenable, a leading cloud exposure management company, has identified a privilege escalation vulnerability in Google Cloud Run, named ImageRunner. This security flaw could have allowed attackers to bypass permissions, access private container images, and expose sensitive data. The vulnerability stemmed from Cloud Run’s inherited elevated permissions, enabling attackers with edit permissions to manipulate container images.
Tenable highlights that this issue exemplifies the Jenga® Concept, where security weaknesses in cloud service layers cascade into dependent services, increasing overall risk. Google has since addressed ImageRunner, requiring no additional user action. However, Tenable urges organizations to adopt proactive security measures, including following the least privilege model, mapping hidden cloud dependencies, and reviewing access logs for anomalies.
















