Vulnerability Description
A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow access to sensitive information in log files.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tableau | Tableau Server | >= 2018.1, <= 2020.2 |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://help.salesforce.com/apex/HTViewSolution?urlname=Sensitive-information-diThird Party Advisory
- https://help.salesforce.com/articleView?id=000354158&type=1&mode=1Third Party Advisory
- https://help.salesforce.com/apex/HTViewSolution?urlname=Sensitive-information-diThird Party Advisory
- https://help.salesforce.com/articleView?id=000354158&type=1&mode=1Third Party Advisory
FAQ
What is CVE-2020-6938?
CVE-2020-6938 is a vulnerability with a CVSS score of 7.5 (HIGH). A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow access to sensitive information in log files.
How severe is CVE-2020-6938?
CVE-2020-6938 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6938?
Check the references section above for vendor advisories and patch information. Affected products include: Tableau Tableau Server, Linux Linux Kernel, Microsoft Windows.