An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model.
References
Configurations
No configuration.
History
21 Nov 2024, 09:47
Type | Values Removed | Values Added |
---|---|---|
References | () https://cloud.google.com/looker/docs/best-practices/query-id-update-instructions - | |
Summary |
|
22 May 2024, 17:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-22 17:16
Updated : 2024-11-21 09:47
NVD link : CVE-2024-5166
Mitre link : CVE-2024-5166
CVE.ORG link : CVE-2024-5166
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key