CVE-2025-52454: SSRF
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52454?
CVE-2025-52454 is classified as a server-side request forgery (SSRF) vulnerability.
How does CVE-2025-52454 affect Salesforce Tableau Server?
CVE-2025-52454 allows for resource location spoofing in affected versions of Salesforce Tableau Server.
What versions of Salesforce Tableau Server are affected by CVE-2025-52454?
CVE-2025-52454 affects Salesforce Tableau Server versions before 2025.1.3, 2024.2.12, and 2023.3.19.
How do I fix CVE-2025-52454?
To resolve CVE-2025-52454, upgrade to a version of Salesforce Tableau Server that is not affected by the vulnerability.
What is resource location spoofing in the context of CVE-2025-52454?
In the context of CVE-2025-52454, resource location spoofing involves misleading the server into making requests to unintended resources.