Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.
References
Link | Resource |
---|---|
https://github.com/getredash/redash/issues/5426 | Issue Tracking Third Party Advisory |
https://github.com/getredash/redash/releases | Release Notes Third Party Advisory |
https://github.com/getredash/redash/issues/5426 | Issue Tracking Third Party Advisory |
https://github.com/getredash/redash/releases | Release Notes Third Party Advisory |
Configurations
History
21 Nov 2024, 05:28
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/getredash/redash/issues/5426 - Issue Tracking, Third Party Advisory | |
References | () https://github.com/getredash/redash/releases - Release Notes, Third Party Advisory |
Information
Published : 2021-03-18 20:15
Updated : 2024-11-21 05:28
NVD link : CVE-2020-36144
Mitre link : CVE-2020-36144
CVE.ORG link : CVE-2020-36144
JSON object : View
Products Affected
redash
- redash
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')