Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-43780

Опубликовано: 24 нояб. 2021
Источник: nvd
CVSS3: 6.8
CVSS3: 8.8
CVSS2: 6
EPSS Низкий

Описание

Redash is a package for data visualization and sharing. In versions 10.0 and priorm the implementation of URL-loading data sources like JSON, CSV, or Excel is vulnerable to advanced methods of Server Side Request Forgery (SSRF). These vulnerabilities are only exploitable on installations where a URL-loading data source is enabled. As of time of publication, the master and release/10.x.x branches address this by applying the Advocate library for making http requests instead of the requests library directly. Users should upgrade to version 10.0.1 to receive this patch. There are a few workarounds for mitigating the vulnerability without upgrading. One can disable the vulnerable data sources entirely, by adding the following env variable to one's configuration, making them unavailable inside the webapp. One can switch any data source of certain types (viewable in the GitHub Security Advisory) to be View Only for all groups on the Settings > Groups > Data Sources screen. For users un

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redash:redash:*:*:*:*:*:*:*:*
Версия до 10.0.1 (исключая)

EPSS

Процентиль: 45%
0.00226
Низкий

6.8 Medium

CVSS3

8.8 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-918
CWE-918

EPSS

Процентиль: 45%
0.00226
Низкий

6.8 Medium

CVSS3

8.8 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-918
CWE-918