Data Security, Vulnerability Management, Patch/Configuration Management

Tenable discovers 9 LeakyLooker vulnerabilities in Google Looker Studio

Tech Radar reports that nine vulnerabilities, collectively named LeakyLooker, have been discovered in Google Looker Studio. These flaws could allow attackers to execute arbitrary SQL queries and access sensitive data within Google Cloud environments.

Security researchers at Tenable identified the nine flaws, which impact users of various Looker Studio data connectors, including Google Sheets and PostgreSQL. The vulnerabilities exploit the tool's "Live Data" architecture, enabling zero-click or one-click attacks. Specific issues include cross-tenant unauthorized access via SQL injection on database connectors and stored credentials, data source leaks through hyperlinks and image rendering, and SQL injection on BigQuery and Spanner. A particularly concerning flaw involved a "Sticky Credential" logic error in the "Copy Report" feature, allowing attackers to retain original owner credentials when cloning reports.

Google has since patched all nine vulnerabilities globally. Tenable advises users to regularly review access permissions for both public and private reports to mitigate potential risks and ensure data security.

Source: Tech Radar

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds