CVE-2025-12742
- EPSS 0.06%
- Veröffentlicht 25.11.2025 05:38:47
- Zuletzt bearbeitet 25.11.2025 22:16:16
A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Teradata driver parameters. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Loo...
CVE-2025-12741
- EPSS 0.09%
- Veröffentlicht 24.11.2025 11:35:33
- Zuletzt bearbeitet 25.11.2025 22:16:16
A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, cause Looker to execute a malicious command. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been...
CVE-2025-12414
- EPSS 0.08%
- Veröffentlicht 20.11.2025 10:32:52
- Zuletzt bearbeitet 21.11.2025 15:13:59
An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email address string normalization.Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Loo...
CVE-2025-12405
- EPSS 0.04%
- Veröffentlicht 10.11.2025 09:27:45
- Zuletzt bearbeitet 12.11.2025 16:19:59
An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors. A Looker Studio user with report view access could make a copy of the report and execute arbitrary SQL that would run on the data sourc...
CVE-2025-12409
- EPSS 0.03%
- Veröffentlicht 10.11.2025 08:59:15
- Zuletzt bearbeitet 12.11.2025 16:19:59
A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration from BigQuery data sources. By creating a malicious report with native functions enabled, and having the victim access the report, an attacker could ex...
CVE-2025-12397
- EPSS 0.03%
- Veröffentlicht 10.11.2025 08:55:05
- Zuletzt bearbeitet 12.11.2025 16:19:59
A SQL injection vulnerability was found in Looker Studio. A Looker Studio user with report view access could inject malicious SQL that would execute with the report owner's permissions. The vulnerability affected to reports with BigQuery as the data...
CVE-2025-12155
- EPSS 0.53%
- Veröffentlicht 10.11.2025 08:49:45
- Zuletzt bearbeitet 12.11.2025 16:19:59
A Command Injection vulnerability, resulting from improper file path sanitization (Directory Traversal) in Looker allows an attacker with Developer permission to execute arbitrary shell commands when a user is deleted on the host system. Looker-host...
CVE-2024-5166
- EPSS 0.07%
- Veröffentlicht 22.05.2024 17:16:15
- Zuletzt bearbeitet 22.07.2025 20:49:16
An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model.