« Volver al listado

CVE-2024-8912

Estado: AnalizadaAlta (8.9)—

An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined for legitimate users.

There are two Looker versions that are hosted by Looker:

Customer-hosted Looker instances were found to be vulnerable and must be upgraded.

This vulnerability has been patched in all supported versions of customer-hosted Looker, which are available on the Looker download page https://download.looker.com/ .

For Looker customer-hosted instances, please update to the latest supported version of Looker as soon as possible. The versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page:

Detalles técnicos trazas, registros y código del informe original
  *  Looker (Google Cloud core) was found to be vulnerable. This issue has already been mitigated and our investigation has found no signs of exploitation.
  *  Looker (original) was not vulnerable to this issue.

  *  23.12 -> 23.12.123+
  *  23.18 -> 23.18.117+
  *  24.0 -> 24.0.92+
  *  24.6 -> 24.6.77+
  *  24.8 -> 24.8.66+
  *  24.10 -> 24.10.78+
  *  24.12 -> 24.12.56+
  *  24.14 -> 24.14.37+

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

HTTP Request Smuggling (CWE-444) en aplicación web expuesta permite capturar respuestas HTTP destinadas a usuarios legítimos; AV:N sin UI:R implica T1190; impacto es lectura de datos sensibles.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-8912",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-8912",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-11T18:32:06.265105Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "cve-coordination@google.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.9,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "HIGH",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@google.com",
      "affectedData": [
        {
          "vendor": "Google",
          "product": "Looker",
          "versions": [
            {
              "status": "affected",
              "version": "23.12.0",
              "lessThan": "23.12.123",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "23.18.0",
              "lessThan": "23.18.117",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "24.0.0",
              "lessThan": "24.0.92",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "24.6.0",
              "lessThan": "24.6.77",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "24.8.0",
              "lessThan": "24.8.66",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "24.10.0",
              "lessThan": "24.10.78",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "24.12.0",
              "lessThan": "24.12.56",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "24.14.0",
              "lessThan": "24.14.37",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Customer-hosted instances"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Google",
          "product": "Looker",
          "versions": [
            {
              "status": "affected",
              "version": "23.6",
              "versionType": "custom",
              "lessThanOrEqual": "24.14"
            }
          ],
          "platforms": [
            "Google Cloud core instances"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-10-11T19:15:11.110",
  "references": [
    {
      "url": "https://cloud.google.com/looker/docs/best-practices/security-bulletin-09-16-24",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve-coordination@google.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-444"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined for legitimate users.\n\nThere are two Looker versions that are hosted by Looker:\n\n  *  Looker (Google Cloud core) was found to be vulnerable. This issue has already been mitigated and our investigation has found no signs of exploitation.\n  *  Looker (original) was not vulnerable to this issue.\n\n\nCustomer-hosted Looker instances were found to be vulnerable and must be upgraded.\n\nThis vulnerability has been patched in all supported versions of customer-hosted Looker, which are available on the  Looker download page https://download.looker.com/ .\n\nFor Looker customer-hosted instances, please update to the latest supported version of Looker as soon as possible. The versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page:\n\n  *  23.12 -> 23.12.123+\n  *  23.18 -> 23.18.117+\n  *  24.0 -> 24.0.92+\n  *  24.6 -> 24.6.77+\n  *  24.8 -> 24.8.66+\n  *  24.10 -> 24.10.78+\n  *  24.12 -> 24.12.56+\n  *  24.14 -> 24.14.37+"
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de contrabando de solicitudes HTTP en Looker permitió que un atacante no autorizado capturara respuestas HTTP destinadas a usuarios legítimos. Hay dos versiones de Looker alojadas por Looker: * Se descubrió que Looker (núcleo de Google Cloud) era vulnerable. Este problema ya se ha mitigado y nuestra investigación no ha encontrado signos de explotación. * Looker (original) no era vulnerable a este problema. Se descubrió que las instancias de Looker alojadas por el cliente eran vulnerables y deben actualizarse. Esta vulnerabilidad se ha corregido en todas las versiones compatibles de Looker alojadas por el cliente, que están disponibles en la página de descarga de Looker https://download.looker.com/ . Para las instancias de Looker alojadas por el cliente, actualice a la última versión compatible de Looker lo antes posible. Las versiones a continuación se han actualizado para proteger contra esta vulnerabilidad. Puede descargar estas versiones en la página de descarga de Looker: * 23.12 -> 23.12.123+ * 23.18 -> 23.18.117+ * 24.0 -> 24.0.92+ * 24.6 -> 24.6.77+ * 24.8 -> 24.8.66+ * 24.10 -> 24.10.78+ * 24.12 -> 24.12.56+ * 24.14 -> 24.14.37+"
    }
  ],
  "lastModified": "2026-06-17T08:23:32.913",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:cloud_looker:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC4484C2-20F0-45FE-92D0-03FCDF9EF7CA",
              "versionEndExcluding": "23.12.123",
              "versionStartIncluding": "23.12"
            },
            {
              "criteria": "cpe:2.3:a:google:cloud_looker:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9334915-5D2B-45CB-9286-42307094445A",
              "versionEndExcluding": "23.18.117",
              "versionStartIncluding": "23.18"
            },
            {
              "criteria": "cpe:2.3:a:google:cloud_looker:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "954CFC0A-7632-4B43-BAC5-78D63E2CE3AD",
              "versionEndExcluding": "24.0.92",
              "versionStartIncluding": "24.0"
            },
            {
              "criteria": "cpe:2.3:a:google:cloud_looker:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0FD97D2-8EE5-4BF6-B38F-E187A7972804",
              "versionEndExcluding": "24.6.77",
              "versionStartIncluding": "24.6"
            },
            {
              "criteria": "cpe:2.3:a:google:cloud_looker:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4857875-6656-4711-9BAA-3EF8506F8E81",
              "versionEndExcluding": "24.8.66",
              "versionStartIncluding": "24.8"
            },
            {
              "criteria": "cpe:2.3:a:google:cloud_looker:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D802F86A-8BB3-4D64-9899-610893BDD0B9",
              "versionEndExcluding": "24.10.78",
              "versionStartIncluding": "24.10"
            },
            {
              "criteria": "cpe:2.3:a:google:cloud_looker:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "331DDAF4-C8B9-44F0-8F55-0FCCFC65A4A4",
              "versionEndExcluding": "24.12.56",
              "versionStartIncluding": "24.12"
            },
            {
              "criteria": "cpe:2.3:a:google:cloud_looker:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA7AAC28-6AD0-4875-AE6C-504A85C5974D",
              "versionEndExcluding": "24.14.37",
              "versionStartIncluding": "24.14"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@google.com"
}