Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Redash: Open redirect vulnerability in post-login redirect handling
Vulnerability Description
Redash is a package for data visualization and sharing. From 5.0.2 to 26.3.0, the get_next_path() function in Redash's authentication module stripped the scheme and netloc from user-supplied next parameters but did not normalize multiple leading slashes, allowing a crafted login URL such as /login?next=////evil.com to redirect users to an external attacker-controlled site after authentication.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
指向未可信站点的URL重定向(开放重定向)
Vulnerability Title
Redash 输入验证错误漏洞
Vulnerability Description
Redash是以色列Redash公司开源的一套数据整合分析解决方案。该产品支持数据整合、数据可视化、查询编辑和数据共享等。 Redash 5.0.2版本至26.3.0版本存在输入验证错误漏洞,该漏洞源于get_next_path()函数未规范化多个前导斜杠,可能导致用户认证后被重定向到外部攻击者控制的站点。
CVSS Information
N/A
Vulnerability Type
N/A