Description
An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2036 | An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1. |
Github GHSA |
GHSA-cmjc-52fg-9f7j | Apache Superset vulnerable to Exposure of Sensitive Information |
References
History
Mon, 21 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-10-21T15:08:55.113Z
Reserved: 2023-04-17T11:47:18.487Z
Link: CVE-2023-30776
Updated: 2024-08-02T14:37:15.407Z
Status : Modified
Published: 2023-04-24T16:15:08.000
Modified: 2024-11-21T08:00:52.983
Link: CVE-2023-30776
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA