PT-2020-13229 · Redash · Redash

0Xbadca7

·

Published

2020-06-11

·

Updated

2024-03-06

·

CVE-2020-12725

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Redash open-source versions 8.0.0 and prior
Description An authenticated Server-Side Request Forgery (SSRF) was discovered via the JSON data source. This issue provides flexibility in crafting HTTP requests, such as adding headers and selecting any HTTP verb. Possibly, other connectors are affected.
Recommendations For Redash open-source versions 8.0.0 and prior, consider disabling the JSON data source as a temporary workaround until a patch is available. Restrict access to potentially vulnerable connectors to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

BIT-REDASH-2020-12725
CVE-2020-12725

Affected Products

Redash