QID 150756

Date Published: 2023-12-11

QID 150756: Apache Superset Prior to 2.1.2 Multiple Security Vulnerabilities

Apache Superset is an open-source software application for data exploration and data visualization able to handle data at petabyte scale.

Affected versions of Apache Superset has multiple vulnerabilities:
CVE-2023-43701: Stored XSS on API endpoint.
CVE-2023-40610: Privilege escalation with default examples database.
CVE-2023-42501: Unnecessary read permissions within the Gamma role.

Affected Versions:
Apache Superset before 2.1.2

QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request and checks the response body to confirm if the host is running vulnerable version of Apache Superset.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to Apache Superset 2.1.2 to latest version to remediate this vulnerability.
    For more information regarding this vulnerability please refer:
    CVE-2023-43701
    CVE-2023-40610
    CVE-2023-42501
    Vendor References

    CVEs related to QID 150756

    Software Advisories
    Advisory ID Software Component Link
    Apache Superset URL Logo downloads.apache.org/superset/2.1.2/