Looker HTTP Request Smuggling Vulnerability
CVE-2024-8912

7.5HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
11 October 2024

What is CVE-2024-8912?

A notable HTTP Request Smuggling vulnerability was identified in Looker, creating the potential for unauthorized attackers to intercept HTTP responses intended for legitimate users. This vulnerability specifically affects customer-hosted Looker instances, necessitating an urgent update to the latest supported versions outlined on the Looker download page. It has been confirmed that the Google Cloud core version of Looker was not vulnerable and has already been mitigated, indicating that administrators of customer-hosted versions need to act promptly to secure their systems from any potential exploit.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Looker Customer-hosted instances 23.12.0 < 23.12.123

Looker Customer-hosted instances 23.18.0 < 23.18.117

Looker Customer-hosted instances 24.0.0 < 24.0.92

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.