CVE-2023-36387
published 2023-09-06CVE-2023-36387: An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database…
PriorityP429medium5.4CVSS 3.1
AVNACLPRLUINSUCNILAL
EPSS
0.84%
53.5th percentile
An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | superset | <= 2.1.0 | — |
| apache_software_foundation | apache_superset | <= 2.1.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Superset has improper default REST API permission for Gamma users
osv·2023-09-06
CVE-2023-36387 [MEDIUM] Apache Superset has improper default REST API permission for Gamma users
Apache Superset has improper default REST API permission for Gamma users
An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.
GHSA
Apache Superset has improper default REST API permission for Gamma users
ghsa·2023-09-06
CVE-2023-36387 [MEDIUM] CWE-281 Apache Superset has improper default REST API permission for Gamma users
Apache Superset has improper default REST API permission for Gamma users
An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-09-06
Published