QID 150679
Date Published: 2023-05-10
QID 150679: Apache Superset Insecure Default Configuration Vulnerability (CVE-2023-27524)
Apache Superset is an open-source software application for data exploration and data visualization able to handle data at petabyte scale.
Apache Superset is vulnerable to Session Validation attacks. Attackers can exploit this vulnerability to authenticate and gain access to unauthorized resources if the default configured SECRET_KEY has not been changed according to installation instructions. It is important to note that Superset administrators who have already changed the default value for the SECRET_KEY config are not affected by this vulnerability.
Affected Versions:
Apache Superset versions up to and including 2.0.1
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request and checks the response body to confirm if the host is running vulnerable version of Apache Superset.
Attackers could potentially authenticate and gain access to unauthorized resources.
- Apache Superset -
lists.apache.org/thread/n0ftx60sllf527j7g11kmt24wvof8xyk
CVEs related to QID 150679
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Superset |
|