ZeroHour

CVE-2023-36388

CVSS 3.1
5.4 medium
EPSS
1%p64
Published
()
Modified
Description

Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possible SSRF.

Vendors
apache
Products
superset
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news