CVE-2020-36144

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
18/03/2021
Last modified:
24/03/2021

Description

Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redash:redash:8.0.0:*:*:*:*:*:*:*