Authenticated Server-Side Request Forgery Vulnerability in Redash Open Source Data Visualization Tool
CVE-2020-12725
7.2HIGH
What is CVE-2020-12725?
Havoc Research identified an authenticated Server-Side Request Forgery (SSRF) in the JSON data source of Redash, an open-source data visualization tool. This vulnerability affects Redash versions 8.0.0 and earlier, allowing attackers to manipulate HTTP requests by adding custom headers and choosing any HTTP method. As a result, this SSRF could potentially lead to unauthorized access to internal services and sensitive data. It is essential to review and update your Redash installation to mitigate this vulnerability.