ZeroHour

CVE-2023-36387

CVSS 3.1
5.4 medium
EPSS
1%p65
Published
()
Modified
Description

An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.

Vendors
apache
Products
superset
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

In the news

No ingested article mentions this CVE yet.