Vulnerabilities (CVE)

Filtered by vendor Lightdash Subscribe
Filtered by product Lightdash
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-35844 1 Lightdash 1 Lightdash 2024-11-21 N/A 7.5 HIGH
packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that an intended file extension (.csv or .png) is used.