TotalCloud Insights: Uncovering the Hidden Dangers in Google Cloud Dataproc
ID: 8b5e3f62-b46c-5056-a908-5a1720e8c5f4
STIX ID: report--8b5e3f62-b46c-5056-a908-5a1720e8c5f4
Feed Name: Qualys Blog
This Qualys TotalCloud advisory details a misconfiguration risk in Google Cloud Dataproc where unauthenticated HDFS (NameNode on 9870) and YARN (ResourceManager on 8088) web UIs can be reachable when clusters use the default VPC or share a VPC with other workloads; an attacker who compromises a Compute Engine instance or other service in the same VPC can tunnel to these interfaces to access or manipulate cluster data. The report explains the attack flow, contrasts GCP's behavior with AWS and Azure, and recommends network segmentation, avoiding default VPCs, vulnerability management, and encryption with customer-managed keys; Qualys TotalCloud will add a control to detect Dataproc clusters using the default VPC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
