QID 376016
Date Published: 2021-11-15
QID 376016: Tableau Server Sensitive Information Exposure Vulnerability (ADV-2021-017)
Tableau Server is a Business Intelligence application that allows its users to organize, edit, share, and collaborate on Tableau dashboards.
Tableau discovered that some versions of Tableau Server are logging OAuth Client IDs and Client Secrets in plain text in Tableau Server logs.
Affected Versions:
Tableau Server on Linux 2021.1 through 2021.1.5
Tableau Server on Linux 2021.2 through 2021.2.2
Tableau Server on Linux 2021.3 through 2021.3.1
Tableau Server on Windows 2021.1 through 2021.1.5
Tableau Server on Windows 2021.2 through 2021.2.2
Tableau Server on Windows 2021.3 through 2021.3.1
QID Detection Logic (Authenticated)
This QID checks for the file version of tabsvc.exe for Tableau Server
Oauth Client IDs and Client Secrets associated with the connectors are visible to users with access to their orgs Tableau Server logs, resulting in the potential for unauthorized access to customers OAuth login pages.
- ADV-2021-017 -
help.salesforce.com/s/articleView?id=000363324&type=1
CVEs related to QID 376016
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ADV-2021-017 |
|