CVE-2024-12236 - CVE House
Back to Database
Status published Medium CVE-2024-12236

Use of Custom URI for media inputs with VPC-SC enabled potentially leads to data exfiltration

Vulnerability Description

A security issue exists in Vertex Gemini API for customers using VPC-SC. By utilizing a custom crafted file URI for image input, data exfiltration is possible due to requests being routed outside the VPC-SC security perimeter, circumventing the intended security restrictions of VPC-SC. No further fix actions are needed. Google Cloud Platform implemented a fix to return an error message when a media file URL is specified in the fileUri parameter and VPC Service Controls is enabled. Other use cases are unaffected.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-12236

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Google Cloud Platform

View all reports →

Affected Software

Vertex Gemini API
Vulnerable Versions:
0

Timeline

Official Publish: December 10th, 2024
Last Modified: January 30th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)