1 results (0.002 seconds)
CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 0

CVE-2024-12236 – Use of Custom URI for media inputs with VPC-SC enabled potentially leads to data exfiltration
https://notcve.org/view.php?id=CVE-2024-12236
10 Dec 2024 — A security issue exists in Vertex Gemini API for customers using VPC-SC. By utilizing a custom crafted file URI for image input, data exfiltration is possible due to requests being routed outside the VPC-SC security perimeter, circumventing the intended security restrictions of VPC-SC. No further fix actions are needed. Google Cloud Platform implemented a fix to return an error message when a media file URL is specified in the fileUri parameter and VPC Service Controls is enabled. Other use cases are unaffe... • https://cloud.google.com/vertex-ai/generative-ai/docs/security-bulletins#gcp-2024-063 • CWE-755: Improper Handling of Exceptional Conditions •