CVE-2024-5166

An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
GoogleCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
VendorProductVersion
googlelooker
23.18
googlelooker
23.20
googlelooker
24.0
googlelooker
24.2
googlelooker
24.4
googlelooker
24.6
googlelooker
24.8
googlelooker
24.10
googlelooker
24.12
googlelooker
24.14
googlelooker
24.16
googlelooker
24.18
googlelooker
24.20
𝑥
= Vulnerable software versions