CVE-2023-36388
published 2023-09-06CVE-2023-36388: Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possible SSRF.
medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possible SSRF.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | superset | <= 2.1.0 | — |
| apache_software_foundation | apache_superset | <= 2.1.0 | — |