CVE-2020-36144

Publication date

2021-03-18 19:37:28

Family

mitre

State

PUBLISHED

Description

Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.