CVE-2023-25504

CVSS V2 None CVSS V3 None
Description
A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery attacks and query internal resources on behalf of the server where Superset is deployed. This vulnerability exists in Apache Superset versions up to and including 2.0.1.
Overview
  • CVE ID
  • CVE-2023-25504
  • Assigner
  • security@apache.org
  • Vulnerability Status
  • Undergoing Analysis
  • Published Version
  • 2023-04-17T17:15:07
  • Last Modified Date
  • 2023-04-18T03:15:07
History
Created Old Value New Value Data Type Notes
2023-04-17 18:00:47 Added to TrackCVE
2023-04-17 18:00:48 Weakness Enumeration new
2023-04-18 04:00:32 2023-04-18T03:15:07 CVE Modified Date updated
2023-04-18 04:00:35 References updated
2023-04-24 11:00:56 Awaiting Analysis Undergoing Analysis Vulnerability Status updated