QID 981944
QID 981944: Python (pip) Security Update for apache-superset (GHSA-fxjm-wvj9-9c39)
An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fxjm-wvj9-9c39 for updates pertaining to this vulnerability.
Vendor References
- GHSA-fxjm-wvj9-9c39 -
github.com/advisories/GHSA-fxjm-wvj9-9c39
CVEs related to QID 981944
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fxjm-wvj9-9c39 | apache-superset |
|