craftcms/google-cloud is vulnerable to Information Disclosure
32
Low Risk
Affected versions of this package are vulnerable to information disclosure due to insufficient access control on certain controller actions. Specifically, requests to load bucket metadata could be executed without requiring administrative privileges, potentially exposing internal configuration or other sensitive details to unauthorized users. The issue is fixed by enforcing administrator-only access checks on those endpoints, preventing unauthorized access and mitigating the information disclosure risk.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/google-cloud is vulnerable to Information Disclosure in versions 1.0.0 - 2.2.0.
Upgrade the craftcms/google-cloud library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant