Severity
5.4MEDIUM
EPSS
0.0%
top 94.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 6

Description

An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:LExploitability: 2.8 | Impact: 2.5

Affected Packages3 packages

Patches

🔴Vulnerability Details

3
OSV
Apache Superset has improper default REST API permission for Gamma users2023-09-06
GHSA
Apache Superset has improper default REST API permission for Gamma users2023-09-06
CVEList
Apache Superset: Improper API permission for low privilege users2023-09-06
CVE-2023-36387 (MEDIUM CVSS 5.4) | An improper default REST API permis | cvebase.io