vulns.co
/
GKData.io MCP

CLSecurity theme

Cloud permissions and isolation.

Service identities, IAM boundaries, tenant isolation, and delegated authority. 15 disclosures · 9 related references · 4 diagrams.

Connected collection

Disclosures

Google AZAuthorization and tenant boundaries

Google Mamba temporary outputs lacked access isolation

Mamba received a distinct USD 37,604.40 award. The case illustrates why temporary processing output needs explicit access isolation, with retrieval dependencies kept separate from standalone impact.

USD 37,604.40reported awardRead

Connected collection

Related learning

Amazon Web Services Implementation Guide

AWS IAM security best practices for workload identities

Use this guide to review machine identity design: favor short-lived role credentials for workloads, limit permissions to required actions and resources, and retire unnecessary access. It also explains policy validation,…

Reviewed 2026-10-02Read

National Institute of Standards and Technology Architecture Guide

NIST SP 800-190: Application Container Security Guide

A foundational model of container images, registries, orchestration, runtimes and host security. It explains shared-kernel risk, workload separation, constrained runtime permissions and lifecycle maintenance.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

Authorization Cheat Sheet

Practical design guidance covering least privilege, deny-by-default behavior, consistent per-request decisions, failure handling, logging, and authorization regression tests.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Server-Side Request Forgery Prevention

Explains destination validation and network isolation for server-initiated requests, distinguishing fixed trusted destinations from services that need broader external access.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Transaction Authorization

Explains operation-specific approval: show significant transaction details, preserve authorized data, enforce valid state transitions and recheck authorization at execution.

Reviewed 2026-10-02Read

Connected collection

Visual models

Untrusted input is parsed with memory safety and limited privileges. A bounded typed result still requires an independent meaning and authorization check before any scoped operation; failed checks reject the request.

Conceptual model Diagram

Parsing safety and action authority

Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.

Reviewed 2026-10-02Read
A requested destination passes consistent parsing, application policy and independent network egress checks. Invalid input or either policy failure is rejected. Only an approved destination is requested.

Conceptual model Diagram

Layer server-request destination controls

Original conceptual defense-in-depth model linked to the historical Shopify Exchange case and OWASP guidance. It is not a vendor architecture diagram. Policy must fit the service’s destination requirements.

Reviewed 2026-10-02Read
A verified workload identity and a requested operation enter an independent authorization decision. Policy checks the role, action, resource and tenant together. Only the approved resource scope is allowed; other requests are denied. Both decisions produce an audit record.

Conceptual model Diagram

Keep workload authority tenant-scoped

Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.

Reviewed 2026-10-02Read

Related learning follows the topic crosswalk or an explicit diagram relationship. It does not classify a resource as a finding. Topics overlap, so their counts should not be added together.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software