S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-35844 Scanner

CVE-2023-35844 scanner - Directory Traversal vulnerability in Lightdash

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that an intended file extension (.csv or .png) is used.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Sep 18, 2026View on NVD →
Detail

Lightdash is a business intelligence tool that enables users to perform data exploration, visualization and sharing. The tool is used in data analytics, providing companies with the ability to make data-driven decisions and insights. Lightdash is designed to make data accessible and understandable to everyone with its intuitive interface and powerful features. With Lightdash, businesses can quickly gather insights to make better decisions, track their performance, and identify trends. 

The CVE-2023-35844 vulnerability detected in Lightdash before version 0.510.3 was related to insecure file endpoints. Specifically, the issue permitted directory traversal or the use of unintended file extensions. Attackers could exploit this vulnerability to gain unauthorized access, circumvent security controls and execute arbitrary code. It is considered a critical vulnerability and poses a significant risk to the security and privacy of the data processed by Lightdash. 

Exploiting the CVE-2023-35844 vulnerability could potentially lead to severe consequences for businesses that use Lightdash for their data analytics needs. Attackers could steal or manipulate sensitive data, inject malware, and compromise the integrity of the system. The breach could lead to the loss of trust and reputation, financial losses, and legal repercussions. The sensitive data could include financial records, customer information, and intellectual property, among others. 

Thanks to s4e.io's pro features, businesses can easily and quickly stay informed about vulnerabilities in their digital assets. The platform provides comprehensive vulnerability assessments and prioritizes the findings based on the potential risk. s4e.io also offers actionable recommendations and best practices to address the identified vulnerabilities. By leveraging the platform's capabilities, businesses can proactively protect their systems and data from cyber threats, including the CVE-2023-35844 vulnerability in Lightdash.

 

REFERENCES

Solution Advice

To protect against the CVE-2023-35844 vulnerability, businesses using Lightdash can take the following precautions: 

  • Update Lightdash to the latest version that fixes the vulnerability. 
  • Implement a web application firewall (WAF) to detect and block malicious traffic. 
  • Disable directory listing on the web server to prevent attackers from traversing directories. 
  • Enforce file upload policies that only allow intended file extensions (.csv or .png) and block others. 
  • Regularly monitor the system and audit the logs for suspicious activities. 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-35844 scanner - Directory Traversal vulnerability in Lightdash | S4E