CVE-2020-12725: Redash
High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.
Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-source 8.0.0 and prior. Possibly, other connectors are affected. The SSRF is potent and provides a lot of flexibility in terms of being able to craft HTTP requests e.g., by adding headers, selecting any HTTP verb, etc.
Affected products
- Redash Redash: up to and including 8.0.0
Published 2020-06-11. Last modified 2026-06-17.