VulnerabilityModified
CVE-2020-36144
Redash 8.0.0 is affected by LDAP Injection.
MEDIUM 5.3EPSS 0.93%
Does this matter?
Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.
Description
Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- redash/redash
- Source
- cve@mitre.org
References
- https://github.com/getredash/redash/issues/5426Issue Tracking, Third Party Advisory
- https://github.com/getredash/redash/releasesRelease Notes, Third Party Advisory
- https://github.com/getredash/redash/issues/5426Issue Tracking, Third Party Advisory
- https://github.com/getredash/redash/releasesRelease Notes, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.