Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A dashboard that contains HTML elements which point to a threat actor controlled source can trigger an SSRF request when exported, via a POST request to /api/v1/dashboards//export. The forged request contains the value of the exporting user’s session token. A threat actor could obtain the session token of any user who exports the dashboard. The obtained session token can be used to perform actions as the victim on the application, resulting in session takeover.
History

Tue, 03 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Lightdash
Lightdash lightdash
CPEs cpe:2.3:a:lightdash:lightdash:*:*:*:*:*:*:*:*
Vendors & Products Lightdash
Lightdash lightdash
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 30 Aug 2024 22:45:00 +0000

Type Values Removed Values Added
Description Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A dashboard that contains HTML elements which point to a threat actor controlled source can trigger an SSRF request when exported, via a POST request to /api/v1/dashboards//export. The forged request contains the value of the exporting user’s session token. A threat actor could obtain the session token of any user who exports the dashboard. The obtained session token can be used to perform actions as the victim on the application, resulting in session takeover.
Weaknesses CWE-201
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Mandiant

Published: 2024-08-30T22:25:48.431Z

Updated: 2024-09-03T14:50:25.611Z

Reserved: 2024-07-08T21:24:57.730Z

Link: CVE-2024-6586

cve-icon Vulnrichment

Updated: 2024-09-03T14:50:16.434Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-30T23:15:12.747

Modified: 2024-09-03T15:35:16.577

Link: CVE-2024-6586

cve-icon Redhat

No data.