Google Looker: vulnerabilidades y CVE
Google Looker tiene 9 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses8
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-12742 | Alta (7.5) | 0.24% | — | 25 nov 2025 | A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Teradata driver parameters. Looker-hosted and Self-hosted were found to be vulnerable. This issue has… |
| CVE-2025-12741 | Alta (7.7) | 0.24% | — | 24 nov 2025 | A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, cause Looker to execute a malicious command. Looker-hosted and Self-hosted were found to be… |
| CVE-2025-12740 | Alta (7.7) | 0.24% | — | 24 nov 2025 | A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML, cause Looker to execute a malicious command, due to inadequate filtering of the driver's… |
| CVE-2025-12739 | Alta (7.3) | 0.31% | — | 24 nov 2025 | An attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would execute an attacker-supplied script. Exploitation required at least one Looker extension installed on… |
| CVE-2025-12414 | Crítica (9.2) | 0.46% | — | 20 nov 2025 | An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email address string normalization.Looker-hosted and Self-hosted were found to be vulnerable. This issue has… |
| CVE-2025-12743 | Media (6) | 0.27% | — | 19 nov 2025 | The Looker endpoint for generating new projects from database connections allows users to specify "looker" as a connection name, which is a reserved internal name for Looker's internal MySQL database. The schemas… |
| CVE-2025-12472 | Alta (7.1) | 0.25% | — | 19 nov 2025 | An attacker with a Looker Developer role could manipulate a LookML project to exploit a race condition during Git directory deletion, leading to arbitrary command execution on the Looker instance. Looker-hosted and… |
| CVE-2025-12155 | Alta (7.1) | 1.3% | — | 10 nov 2025 | A Command Injection vulnerability, resulting from improper file path sanitization (Directory Traversal) in Looker allows an attacker with Developer permission to execute arbitrary shell commands when a user is deleted… |
| CVE-2024-5166 | Media (6.5) | 0.16% | — | 22 may 2024 | An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model. |