CVE-2023-35844 describes a directory traversal vulnerability in Lightdash versions prior to 0.510.3, specifically within the backend file endpoints. This flaw allows unauthenticated attackers to read arbitrary files on the server by manipulating file paths, bypassing intended file extension restrictions. Rated with a CVSS score of 7.5 (HIGH) and an exceptionally high EPSS score, this vulnerability poses a significant risk of data exposure. While not currently listed on the KEV catalog or showing active social media discussion, public Nuclei templates exist, indicating readily available exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.510.3CPE matchmatch criteria | cpe:2.3:a:lightdash:lightdash:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.