CVE-2020-1932
Summary
| CVE | CVE-2020-1932 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-28 01:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Superset | 0.34.0 | - | All | All |
| Application | Apache | Superset | 0.34.1 | All | All | All |
| Application | Apache | Superset | 0.35.0 | All | All | All |
| Application | Apache | Superset | 0.35.1 | All | All | All |
| Application | Apache | Superset | 0.34.0 | - | All | All |
| Application | Apache | Superset | 0.34.1 | All | All | All |
| Application | Apache | Superset | 0.35.0 | All | All | All |
| Application | Apache | Superset | 0.35.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | MISC | lists.apache.org | Mailing List, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981944 Python (pip) Security Update for apache-superset (GHSA-fxjm-wvj9-9c39)