Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T17:23:09.039Z
Reserved: 2021-01-04T00:00:00
Link: CVE-2020-36144

No data.

Status : Modified
Published: 2021-03-18T20:15:13.020
Modified: 2024-11-21T05:28:48.590
Link: CVE-2020-36144

No data.