CVE-2025-12405
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-269
Gestión de privilegios incorrecta
Fecha de publicación:
10/11/2025
Última modificación:
12/11/2025
Descripción
*** Pendiente de traducción *** An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors.<br />
<br />
A Looker Studio user with report view access could make a copy of the report and execute arbitrary SQL that would run on the data source database due to the stored credentials attached to the report.<br />
<br />
This vulnerability was patched on 21 July 2025, and no customer action is needed.



