CVE-2025-52454

Description

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

Risk Information

Base Score
8.2
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.041

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Salesforce Tableau Server 2023.3.18Windows
Multiple Vulnerabilities are affected in Salesforce Tableau Server 2024.2.11Windows
Multiple Vulnerabilities are affected in Salesforce Tableau Server 2025.1.2Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234