CVE-2023-27524
CVSS V2 None
CVSS V3 None
Description
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config.
Overview
- CVE ID
- CVE-2023-27524
- Assigner
- security@apache.org
- Vulnerability Status
- Awaiting Analysis
- Published Version
- 2023-04-24T16:15:07
- Last Modified Date
- 2023-04-24T16:52:40
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://lists.apache.org/thread/n0ftx60sllf527j7g11kmt24wvof8xyk |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-27524 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27524 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-24 17:01:50 | Added to TrackCVE | |||
2023-04-24 17:01:54 | Weakness Enumeration | new |