ZeroHour

CVE-2020-36144

CVSS 3.1
5.3 medium
EPSS
<1%p59
Published
()
Modified
Description

Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.

Vendors
redash
Products
redash
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.