CVE-2021-1629: Medium severity tableau server vulnerability
Published Mar 26, 2021
·Updated
Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.
Affected Software
7 affected components
Tableau Tableau Server>=2019.4<2019.4.18
Tableau Tableau Server>=2020.1<2020.1.15
Tableau Tableau Server>=2020.2<2020.2.12
Tableau Tableau Server>=2020.3<2020.3.7
Tableau Tableau Server>=2020.4<2020.4.3
Microsoft Windows
Linux Linux kernel
Event History
Mar 26, 2021
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-1629?
CVE-2021-1629 is a vulnerability in Tableau Server that allows attackers to perform open redirection attacks by tricking users into clicking on malicious links embedded in emails.
2
How does Tableau Server validate URLs in emails?
Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.
3
Which versions of Tableau Server are affected by CVE-2021-1629?
Versions 2019.4 to 2020.4 of Tableau Server are affected by CVE-2021-1629.
4
What is the severity of CVE-2021-1629?
CVE-2021-1629 has a severity rating of medium (6.1) according to the National Vulnerability Database (NVD).
5
How can I fix CVE-2021-1629?
To fix CVE-2021-1629, Tableau Server users should update to a patched version provided by the vendor and ensure that URLs in emails are validated properly.