Salesforce Tableau Server
cpe:2.3:a:tableau:server:*:*:*:*:*:*:*, +2 more
- < 2025.1.3
- < 2024.2.12
- < 2023.3.19
A Server-Side Request Forgery (SSRF) vulnerability has been identified in Salesforce Tableau Server on both Windows and Linux platforms, specifically within the Amazon S3 Connector modules. This vulnerability allows for Resource Location Spoofing. Affected Tableau Server versions include those prior to 2025.1.3, 2024.2.12, and 2023.3.19.
Exploitation of this vulnerability allows for Server-Side Request Forgery, with the potential for Resource Location Spoofing.
Users are advised to update Tableau Server to the latest supported Maintenance Release in their branch. This update can be downloaded from the Tableau Server Maintenance Release page. Additionally, customers with a Trino (formerly Presto) driver installed should update their driver to the latest version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.