Skip to content

Tableau Python Server (TabPy) installations may be configured to execute arbitrary python code without authentication

Choose a tag to compare
@jakeichikawasalesforce jakeichikawasalesforce released this 28 Jun 20:49
· 10 commits to master since this release


An unauthenticated attacker could perform remote code execution on TabPy instances that do not have authentication enabled. This release now requires confirmation to continue when starting TabPy without authentication, with a warning that this is an insecure state and not recommended.