CVE-2024-5166: Google Looker
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model.
Affected products
- Google Looker: version 23.18 only; version 23.20 only; version 24.0 only; version 24.2 only; version 24.4 only; version 24.6 only; …
Published 2024-05-22. Last modified 2026-06-17.