@lightdash/common is vulnerable to Improper Authorization
47
Medium Risk
In versions before 0.3069.0, the scheduler send-now path failed to verify whether the requester could view the underlying chart, dashboard, SQL chart, or app, checking only whether they could manage scheduled deliveries. As a result, an editor with create:ScheduledDeliveries could trigger immediate delivery of content stored in a private space they were not authorized to access, causing unauthorized disclosure to the scheduler’s configured recipients. An attacker could exploit this by locating or reusing the UUID of a scheduler tied to restricted content and invoking the send now action, effectively exfiltrating rendered private data without having direct view permission.
You are affected if you are using a version that falls within the vulnerable range.
@lightdash/common is vulnerable to Improper Authorization in versions 0.2020.0 - 0.3068.1.
Upgrade the @lightdash/common library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant