CVE-2022-45438
published 2023-01-16CVE-2022-45438: When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.23%
65.4th percentile
When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | superset | <= 1.5.2 | — |
| apache | superset | — | — |
| apache_software_foundation | apache_superset | <= 1.5.2 | — |
| apache_software_foundation | apache_superset | >= 2.0.0 < 2.0.1 | 2.0.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Superset has Improper Access Control
osv·2023-01-16
CVE-2022-45438 [MEDIUM] Apache Superset has Improper Access Control
Apache Superset has Improper Access Control
When explicitly enabling the feature flag `DASHBOARD_CACHE` (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
GHSA
Apache Superset has Improper Access Control
ghsa·2023-01-16
CVE-2022-45438 [MEDIUM] CWE-284 Apache Superset has Improper Access Control
Apache Superset has Improper Access Control
When explicitly enabling the feature flag `DASHBOARD_CACHE` (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-16
Published