Back to Database
Status published
Medium
CVE-2024-5166
Insecure Direct Object Reference In Looker
Vulnerability Description
An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-5166
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Ionut Cernica with the UiPath Security Team
More from Google Cloud
View All →CVE-2025-9918
Zip Slip in Google SecOps SOAR allows for Remote Code Execution
High
8.7
CVE-2025-9571
Arbitrary Code Execution in Google Cloud Data Fusion via Malicious Artifact Upload
High
8.7
CVE-2025-9118
Dataform Path Traversal
Critical
10
CVE-2025-4600
HTTP Request Smuggling in Google Cloud Classic Application Load Balancer due to Improper Chunked Encoding Validation
High
8.7
CVE-2025-13428
RCE in SecOps SOAR server via user-provided Python packages
High
8.6
Affected Vendor
Google Cloud
View all reports →Affected Software
Looker
Vulnerable Versions:
23.18, 23.20, 24.0, 24.2, 24.4, 24.6, 24.8, 24.10, 24.12, 24.14, 24.16, 24.18, 24.20
Timeline
Official Publish:
May 22nd, 2024
Last Modified:
August 1st, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N