CVE-2023-25504
CVSS V2 None
CVSS V3 None
Description
A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery
attacks and query internal resources on behalf of the server where Superset
is deployed. This vulnerability exists in Apache Superset versions up to and including 2.0.1.
Overview
- CVE ID
- CVE-2023-25504
- Assigner
- security@apache.org
- Vulnerability Status
- Undergoing Analysis
- Published Version
- 2023-04-17T17:15:07
- Last Modified Date
- 2023-04-18T03:15:07
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
http://www.openwall.com/lists/oss-security/2023/04/18/8 | |
https://lists.apache.org/thread/tdnzkocfsqg2sbbornnp9g492fn4zhtx |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-25504 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25504 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 18:00:47 | Added to TrackCVE | |||
2023-04-17 18:00:48 | Weakness Enumeration | new | ||
2023-04-18 04:00:32 | 2023-04-18T03:15:07 | CVE Modified Date | updated | |
2023-04-18 04:00:35 | References | updated | ||
2023-04-24 11:00:56 | Awaiting Analysis | Undergoing Analysis | Vulnerability Status | updated |