S4E just found a high-severity finding from cve-2001-1473 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-41192 Scanner

Detects 'Default Secret Keys' vulnerability in Redash affects v. 10.0.0 and prior.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-41192
6.5
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without explicitly specifying the `REDASH_COOKIE_SECRET` or `REDASH_SECRET_KEY` environment variables, a default value is used for both that is the same across all installations. In such cases, the instance is vulnerable to attackers being able to forge sessions using the known default value. This issue only affects installations where the `REDASH_COOKIE_SECRET or REDASH_SECRET_KEY` environment variables have not been explicitly set. This issue does not affect users of the official Redash cloud images, Redash's Digital Ocean marketplace droplets, or the scripts in the `getredash/setup` repository. These instances automatically generate unique secret keys during installation. One can verify whether one's instance is affected by checking the value of the `REDASH_COOKIE_SECRET` environment variable. If it is `c292a0a3aa32397cdb050e233733900f`, should follow the steps to secure the instance, outlined in the GitHub Security Advisory.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
redashby getredash
<= 10.0.0
Updated Aug 21, 2026View on NVD →
Detail

Redash is a highly popular data visualization and sharing platform that allows its users to make sense of their data by creating dashboards, querying databases, and generating visualizations. Its powerful features allow organizations to make data-driven decisions, visualize performance metrics, monitor marketing campaigns, and much more. With Redash, users can connect to a wide variety of data sources, including SQL databases, NoSQL databases, Big Data platforms, SaaS platforms, and REST APIs.

CVE-2021-41192 is a security vulnerability that has been detected in Redash versions 10.0.0 and prior, where a default value is used for the `REDASH_COOKIE_SECRET` and `REDASH_SECRET_KEY` environment variables. Since the default value is the same across all installations that have not explicitly specified these environment variables, it's easy for attackers to forge sessions and gain unauthorized access to the instance. This can lead to sensitive data being stolen, malware being installed on the server, or the organization's reputation being damaged.

When exploited, the CVE-2021-41192 vulnerability can lead to severe consequences for the affected organization. Attackers can use this vulnerability to gain access to confidential data, steal intellectual property, execute arbitrary code, or sabotage the company's operations by hijacking user sessions. In some cases, these attacks may not be immediately detected, which can lead to prolonged damage and give attackers enough time to extract maximum value from the breach.

Thanks to the pro features of s4e.io, readers of this article can stay up-to-date on the latest vulnerabilities that may be affecting their digital assets. By regularly scanning your network, applications, databases, and other digital assets using our platform, you can quickly identify vulnerabilities and remediate them before they can be exploited. With detailed vulnerability reports, risk assessments, and recommendations for improving security, s4e.io makes it easy for organizations to stay one step ahead of cyber threats and protect their valuable data from being compromised.

 

REFERENCES

Solution Advice

To protect against the CVE-2021-41192 vulnerability, it's essential to follow some precautions that include: 

  • Ensure that the `REDASH_COOKIE_SECRET` and `REDASH_SECRET_KEY` environment variables are explicitly set to unique values across all deployments.
  • Regularly update and patch Redash installations with the latest security fixes.
  • Limit user access to Redash instances to only those who need it and implement strong authentication mechanisms.
  • Encrypted sensitive data using industry-standard encryption techniques to ensure confidentiality.
  • Monitor Redash instances closely for any suspicious activity, log all user activity, and perform regular security audits.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.