U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-8912

Change History

New CVE Received from Google Inc. 10/11/2024 3:15:11 PM

Action Type Old Value New Value
Added Description

								
							
							
						
An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined for legitimate users.

There are two Looker versions that are hosted by Looker:

  *  Looker (Google Cloud core) was found to be vulnerable. This issue has already been mitigated and our investigation has found no signs of exploitation.
  *  Looker (original) was not vulnerable to this issue.


Customer-hosted Looker instances were found to be vulnerable and must be upgraded.

This vulnerability has been patched in all supported versions of customer-hosted Looker, which are available on the  Looker download page https://download.looker.com/ .

For Looker customer-hosted instances, please update to the latest supported version of Looker as soon as possible. The versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page:

  *  23.12 -> 23.12.123+
  *  23.18 -> 23.18.117+
  *  24.0 -> 24.0.92+
  *  24.6 -> 24.6.77+
  *  24.8 -> 24.8.66+
  *  24.10 -> 24.10.78+
  *  24.12 -> 24.12.56+
  *  24.14 -> 24.14.37+
Added CVSS V4.0

								
							
							
						
Google Inc. CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Added CWE

								
							
							
						
Google Inc. CWE-444
Added Reference

								
							
							
						
Google Inc. https://cloud.google.com/looker/docs/best-practices/security-bulletin-09-16-24 [No types assigned]