Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://help.salesforce.com/articleView?id=000357424&type=1&mode=1 | vendor advisory |
http://seclists.org/fulldisclosure/2021/Apr/22 | third party advisory mailing list |
http://packetstormsecurity.com/files/162138/Tableau-Server-Open-Redirection.html | third party advisory vdb entry exploit |