CVE-2024-6586 affects Lightdash version 0.1024.6, allowing authenticated users (Administrator or Editor) to create dashboards containing malicious HTML elements. When such a dashboard is exported, it triggers a Server-Side Request Forgery (SSRF) via a POST request, exfiltrating the exporting user's session token. This vulnerability has a CVSS score of 7.3 (HIGH), indicating a network-based attack with low complexity, requiring user interaction, and leading to high confidentiality and integrity impacts through session takeover. While there is no evidence of active exploitation or Metasploit modules, a Nuclei template exists, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Lightdash | Lightdash | >= 0.1024.6, < 0.1027.2CNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.