CVE-2020-12725 Information
Feb 14, 2021
cve
Description
Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the \JSON\ data source of Redash open-source 8.0.0 and prior. Possibly other connectors are affected. The SSRF is potent and provides a lot of flexibility in terms of being able to craft HTTP requests e.g. by adding headers selecting any HTTP verb etc.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
https://blog.redash.io https://github.com/getredash/redash/commits/master https://github.com/getredash/redash/issues/4869
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.2
Share on: