Researchers Uncover ‘LeakyLooker’ Vulnerabilities in Google Looker Studio
ID: cc19c585-a6dd-536d-9d40-4e79dc8a4888
STIX ID: report--cc19c585-a6dd-536d-9d40-4e79dc8a4888
Feed Name: Infosecurity Magazine (News)
Tenable Research disclosed nine vulnerabilities dubbed LeakyLooker in Google Looker Studio that could enable attackers to execute arbitrary SQL queries, exfiltrate or manipulate data across cloud tenants, and cause billing impacts; issues included SQL injection in connectors, data leaks via report elements, and credential-preserving report-copy behavior. The flaws created 0-click and 1-click attack paths leveraging owner or viewer credentials; Google was notified and deployed global fixes, and organisations are advised to review report sharing and connectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
