CVE-2023-25504
published 2023-04-17CVE-2023-25504: A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct…
medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery
attacks and query internal resources on behalf of the server where Superset
is deployed. This vulnerability exists in Apache Superset versions up to and including 2.0.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | superset | <= 2.0.1 | — |
| apache_software_foundation | apache_superset | <= 2.0.1 | — |