CyberRota Analysis
AI-GeneratedAn unauthorized user with write access to a key vault can exploit this vulnerability to make arbitrary authenticated calls to the Google Cloud KMS API, effectively impersonating an authorized user. This could lead to unauthorized access to sensitive data and compromise client-side encryption mechanisms. Organizations utilizing Google Cloud services with key vault configurations should prioritize addressing this issue to safeguard their data integrity and confidentiality.
Original NVD Description
An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and defeating client-side encryption.