CVE-2021-41192 impacts Redash versions 10.0.0 and prior where administrators have not explicitly set the REDASH_COOKIE_SECRET or REDASH_SECRET_KEY environment variables, leading to the use of a common default value. This allows attackers to forge sessions due to the known default secret. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network attack vector with low complexity, requiring low privileges, and resulting in high integrity impact. While not in CISA's KEV catalog, its high EPSS score (0.87778) and FAUCET Risk Score (99/100) suggest a high likelihood of exploitation. Although no Metasploit or ExploitDB modules exist, Nuclei templates are available for detection, and there's notable community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.0.0CPE matchmatch criteria | cpe:2.3:a:redash:redash:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.