<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Critical Google Looker Flaws Let Attackers Access Multiple Companies' Data

Researchers find critical vulnerabilities in Google Looker, risking data breaches; urgent manual updates needed for on-premises users.
Content Team

Researchers discovered two serious vulnerabilities in Google Looker, a business intelligence platform used by over 60,000 companies including Walmart and Coinbase. The first bug allows SQL injection attacks to steal internal database secrets through error messages. The second, more dangerous flaw enables remote code execution by manipulating Git hooks through a complex exploit chain involving path traversal and race conditions.

On Google Cloud Platform, attackers could potentially access other customers' data due to shared infrastructure. Google has patched both issues, but organizations using on-premises deployments must manually update. The fixes require significant downtime and testing, which may delay critical updates for this central data hub.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo