Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.
References
Link | Resource |
---|---|
https://github.com/getredash/redash/releases | Release Notes Third Party Advisory |
https://github.com/getredash/redash/issues/5426 | Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2021-03-18 13:15
Updated : 2021-03-24 12:38
NVD link : CVE-2020-36144
Mitre link : CVE-2020-36144
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
redash
- redash