Apache Superset: Privilege escalation with default examples database
CVE-2023-40610

6.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
27 November 2023

What is CVE-2023-40610?

A vulnerability exists in Apache Superset versions up to but not including 2.1.2, where improper authorization checks can allow an attacker to exploit a specially crafted CTE SQL statement. This exploit can lead to unauthorized changes in the metadata database, compromising the integrity of authentication and authorization data. By leveraging the default examples database connection, an attacker could gain access to sensitive schema information, escalating privileges and potentially manipulating critical data without the appropriate permissions.

Affected Version(s)

Apache Superset 0 < 2.1.2

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LEXFO for Orange Innovation and Orange CERT-CC at Orange group
.