redash records
6 published records for vendor redash.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 16.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-1188 Initialization of a Resource with an Insecure Default1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2021-43780No exploit | Server-Side Request Forgery (SSRF) in Redashredash · redash · CWE-918 | High8.8 | — | 1.0% | Nov 24, 2021 |
28Monitor | CVE-2021-41192Proof of concept | Insecure default configurationredash · redash · CWE-1188 | Medium6.5 | — | 8.1% | Nov 24, 2021 |
28Monitor | CVE-2020-12725No exploit | Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-source 8.0.0 and priredash · redash · CWE-918 | High7.2 | — | 1.3% | Jun 11, 2020 |
24Monitor | CVE-2026-33213No exploit | Redash: Open redirect vulnerability in post-login redirect handlingredash · redash · CWE-601 | Medium6.1 | — | 0.3% | Jul 15, 2026 |
24Monitor | CVE-2021-43777No exploit | Vulnerability in Redash OAuth2 flows due to misuse of state field (should be a nonce)redash · redash · CWE-352 | Medium6.1 | — | 0.3% | Nov 24, 2021 |
21Monitor | CVE-2020-36144No exploit | Redash 8.0.0 is affected by LDAP Injection.redash · redash · CWE-74 | Medium5.3 | — | 0.9% | Mar 18, 2021 |
- CVE-2021-4378035Monitor
Server-Side Request Forgery (SSRF) in Redash
HighCVSS 8.8No exploitEPSS 1%redash · redashNov 24, 2021
- CVE-2021-4119228Monitor
Insecure default configuration
MediumCVSS 6.5Proof of conceptEPSS 8%redash · redashNov 24, 2021
- CVE-2020-1272528Monitor
Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-source 8.0.0 and pri
HighCVSS 7.2No exploitEPSS 1%redash · redashJun 11, 2020
- CVE-2026-3321324Monitor
Redash: Open redirect vulnerability in post-login redirect handling
MediumCVSS 6.1No exploitEPSS 0%redash · redashJul 15, 2026
- CVE-2021-4377724Monitor
Vulnerability in Redash OAuth2 flows due to misuse of state field (should be a nonce)
MediumCVSS 6.1No exploitEPSS 0%redash · redashNov 24, 2021
- CVE-2020-3614421Monitor
Redash 8.0.0 is affected by LDAP Injection.
MediumCVSS 5.3No exploitEPSS 1%redash · redashMar 18, 2021