low

Dropped active Google Cloud Armor security policy

Published Wed, Sep 29th, 2021
Platforms

Summary

There is a known issue where updating a BackendConfig resource using the v1beta1 API removes an active Google Cloud Armor security policy from its service. If you do not configure Google Cloud Armor on your Ingress resources via the BackendConfig, then this issue does not affect your clusters.

Affected Services

Cloud Armor

Remediation

Dropped Cloud Armor security policies must be manually reattached.

Tracked CVEs

No tracked CVEs

References

Entry Status
Finalized
Disclosure Date
-
Exploitablity Period
-
Known ITW Exploitation
-
Detection Methods
-
Piercing Index Rating
-
Discovered by
-