Tech Radar reports that nine vulnerabilities, collectively named LeakyLooker, have been discovered in Google Looker Studio. These flaws could allow attackers to execute arbitrary SQL queries and access sensitive data within Google Cloud environments.Security researchers at Tenable identified the nine flaws, which impact users of various Looker Studio data connectors, including Google Sheets and PostgreSQL. The vulnerabilities exploit the tool's "Live Data" architecture, enabling zero-click or one-click attacks. Specific issues include cross-tenant unauthorized access via SQL injection on database connectors and stored credentials, data source leaks through hyperlinks and image rendering, and SQL injection on BigQuery and Spanner. A particularly concerning flaw involved a "Sticky Credential" logic error in the "Copy Report" feature, allowing attackers to retain original owner credentials when cloning reports.Google has since patched all nine vulnerabilities globally. Tenable advises users to regularly review access permissions for both public and private reports to mitigate potential risks and ensure data security.Source: Tech Radar
Data Security, Vulnerability Management, Patch/Configuration Management
Tenable discovers 9 LeakyLooker vulnerabilities in Google Looker Studio
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
