Логотип exploitDog
bind:CVE-2020-36144
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-36144

Количество 2

Количество 2

nvd логотип

CVE-2020-36144

почти 5 лет назад

Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-j9jc-frfv-jf2p

больше 3 лет назад

Redash 8.0.0 is affected by LDAP Injection. There is an authentication bypass and information leak through the crafting of special queries, escaping the provided template because the ldap_user = auth_ldap_user(request.form["email"], request.form["password"]) auth_ldap_user(username, password) settings.LDAP_SEARCH_TEMPLATE % {"username": username} code lacks sanitization.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-36144

Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
github логотип
GHSA-j9jc-frfv-jf2p

Redash 8.0.0 is affected by LDAP Injection. There is an authentication bypass and information leak through the crafting of special queries, escaping the provided template because the ldap_user = auth_ldap_user(request.form["email"], request.form["password"]) auth_ldap_user(username, password) settings.LDAP_SEARCH_TEMPLATE % {"username": username} code lacks sanitization.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу