risk
Cloud multi-tenancy isolation and data-scavenging exploits
Adversary exploits multi-tenancy in a cloud environment to observe organizational processes, violates isolation mechanisms, or scavenges data used and deleted by cloud processes, compromising confidentiality and availability.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Network & Communications Security
- Data Protection & Privacy
- Secure Configuration & Change Management
- taxonomy
- nist-800-30-threat-event
- inherent_rating
- medium
Details
- risk_id
- net-cloud-multitenancy-exploit
- category
- cyber_security
- likelihood
- low
- impact
- high
- inherent_rating
- medium
- treatment
- mitigate
- taxonomies
- nist-800-30-threat-event
Source
No record-specific source URL is provided.
Connections
- UC-NET-04 — Isolate system, user, and security functions mitigates Cloud multi-tenancy isolation and data-scavenging exploits
- strength
- related
- rationale
- Partitioning components of differing sensitivity into separate domains reinforces the isolation a multi-tenancy exploit tries to violate.
- UC-NET-05 — Prevent leakage via shared resources and covert channels mitigates Cloud multi-tenancy isolation and data-scavenging exploits
- strength
- primary
- rationale
- Clearing/sanitizing/isolating shared resources between users and processes directly prevents scavenging of data remnants used and deleted by cloud processes.
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines mitigates Cloud multi-tenancy isolation and data-scavenging exploits
- strength
- related
- rationale
- Enforcing secure configuration baselines reduces the cloud/IAM misconfigurations that break tenant isolation, though platform isolation is the operative defense.