CVE-2020-36144: Redash

Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.

Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.

Affected products

  • Redash Redash: version 8.0.0 only

Published 2021-03-18. Last modified 2026-06-17.