CVE-2023-27525Incorrect Authorization in Software Foundation Apache Superset

Severity
4.3MEDIUMNVD
CNA3.1
EPSS
0.2%
top 60.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17

Description

An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
Apache Superset vulnerable to Improper Authorization2023-04-17
OSV
Apache Superset vulnerable to Improper Authorization2023-04-17
CVEList
Apache Superset: Incorrect default permissions for Gamma role2023-04-17
CVE-2023-27525 — Incorrect Authorization | cvebase