Apache Superset: Privilege escalation with default examples database
CVE-2023-40610
What is CVE-2023-40610?
A vulnerability exists in Apache Superset versions up to but not including 2.1.2, where improper authorization checks can allow an attacker to exploit a specially crafted CTE SQL statement. This exploit can lead to unauthorized changes in the metadata database, compromising the integrity of authentication and authorization data. By leveraging the default examples database connection, an attacker could gain access to sensitive schema information, escalating privileges and potentially manipulating critical data without the appropriate permissions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Superset 0 < 2.1.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved