QID 377815
Date Published: 2023-01-04
QID 377815: Tableau Server Path Traversal Remote Code Execution (RCE) Vulnerability
Tableau Server is a Business Intelligence application that allows its users to organize, edit, share, and collaborate on Tableau dashboards.
Tableau discovered that some versions of Tableau Server are logging OAuth Client IDs and Client Secrets in plain text in Tableau Server logs.
Affected Versions:
The following supported versions of Tableau Server are impacted by this issue:
2022.1 - 2022.1.4
2021.4 - 2021.4.9
2021.3 - 2021.3.14
2021.2 - 2021.2.15
2021.1 - 2021.1.17
2020.4 - 2020.4.20
QID Detection Logic (Authenticated)
This QID checks for the file version of tabsvc.exe for Tableau Server
As a result of this code error, unauthorized third parties could have potentially accessed the internal file transfer service and carried out a path traversal attack to perform remote code execution on Tableau Server hosts.
CVEs related to QID 377815
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Tableau Server| |
|