VYPR
High severity7.2NVD Advisory· Published Jun 11, 2020· Updated Jun 17, 2026

CVE-2020-12725

CVE-2020-12725

Description

Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-source 8.0.0 and prior. Possibly, other connectors are affected. The SSRF is potent and provides a lot of flexibility in terms of being able to craft HTTP requests e.g., by adding headers, selecting any HTTP verb, etc.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Redash/Redash3 versions
    cpe:2.3:a:redash:redash:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:redash:redash:*:*:*:*:*:*:*:*range: <=8.0.0
    • (no CPE)
    • (no CPE)range: <=8.0.0
  • osv-coords
    Range: < 8.0.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.