CVE-2021-43777
Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to after login. The `state` parameter should be used for a Cross-Site Request Forgery (CSRF) token, not a static and easily predicted value. This vulnerability does not affect users who do not use Google Login for their instance of Redash.
Leer descripción completaMostrar menos
A patch in the `master` and `release/10.x.x` branches addresses this by replacing `Flask-Oauthlib` with `Authlib` which automatically provides and validates a CSRF token for the state variable. The new implementation stores the next URL on the user session object. As a workaround, one may disable Google Login to mitigate the vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.31%
- Percentil entre todas las CVEs puntuadas: 21
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-352
- CWE-601
Referencias
- https://github.com/getredash/redash/commit/da696ff7f84787cbf85967460fac52886cbe063e
- https://github.com/getredash/redash/security/advisories/GHSA-vhc7-w7r8-8m34
- https://github.com/getredash/redash/commit/da696ff7f84787cbf85967460fac52886cbe063e
- https://github.com/getredash/redash/security/advisories/GHSA-vhc7-w7r8-8m34
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-43777",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "getredash",
"product": "redash",
"versions": [
{
"status": "affected",
"version": "<= 10.0"
}
]
}
]
}
],
"published": "2021-11-24T16:15:14.257",
"references": [
{
"url": "https://github.com/getredash/redash/commit/da696ff7f84787cbf85967460fac52886cbe063e",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/getredash/redash/security/advisories/GHSA-vhc7-w7r8-8m34",
"tags": [
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/getredash/redash/commit/da696ff7f84787cbf85967460fac52886cbe063e",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/getredash/redash/security/advisories/GHSA-vhc7-w7r8-8m34",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-601"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to after login. The `state` parameter should be used for a Cross-Site Request Forgery (CSRF) token, not a static and easily predicted value. This vulnerability does not affect users who do not use Google Login for their instance of Redash. A patch in the `master` and `release/10.x.x` branches addresses this by replacing `Flask-Oauthlib` with `Authlib` which automatically provides and validates a CSRF token for the state variable. The new implementation stores the next URL on the user session object. As a workaround, one may disable Google Login to mitigate the vulnerability."
},
{
"lang": "es",
"value": "Redash es un paquete para visualizar y compartir datos. En la versión 10.0 de Redash y anteriores, la implementación de Google Login (por medio de OAuth) usa incorrectamente el parámetro \"state\" para pasar la siguiente URL a la que redirigir al usuario después de iniciar sesión. El parámetro \"state\" debería ser usado para un token de tipo Cross-Site Request Forgery (CSRF), no un valor estático y fácilmente predecible. Esta vulnerabilidad no afecta a usuarios que no usan Google Login para su instancia de Redash. Un parche en las ramas \"master\" y \"release/10.x.x\" aborda esto sustituyendo \"Flask-Oauthlib\" por \"Authlib\" que proporciona y comprueba automáticamente un token CSRF para la variable de estado. La nueva implementación almacena la siguiente URL en el objeto de sesión del usuario. Como solución, puede ser deshabilitado Google Login para mitigar la vulnerabilidad"
}
],
"lastModified": "2026-06-17T04:11:23.800",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redash:redash:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D326B6D-E6EE-4598-845F-63258E732F02",
"versionEndIncluding": "10.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}