PT-2024-17503 · Google · Vertex Gemini Api

Published

2024-12-10

·

Updated

2025-07-23

·

CVE-2024-12236

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vertex Gemini API (affected versions not specified)
Description A security issue exists in the Vertex Gemini API for customers using VPC-SC. By utilizing a custom crafted file URI for image input, data exfiltration is possible due to requests being routed outside the VPC-SC security perimeter, circumventing the intended security restrictions of VPC-SC. When a media file URL is specified in the fileUri parameter and VPC Service Controls is enabled, an error message is returned. Other use cases are unaffected.
Recommendations No further fix actions are needed, as Google Cloud Platform implemented a fix to return an error message when a media file URL is specified in the fileUri parameter and VPC Service Controls is enabled. As a temporary workaround, consider restricting the use of custom crafted file URIs for image input until the issue is fully resolved. Avoid using the fileUri parameter with media file URLs when VPC Service Controls is enabled to minimize the risk of exploitation.

Fix

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2024-12236

Affected Products

Vertex Gemini Api