Apache Superset: Privilege escalation with default examples database
CVE-2023-40610
8.8HIGH
Summary
A vulnerability exists in Apache Superset versions up to but not including 2.1.2, where improper authorization checks can allow an attacker to exploit a specially crafted CTE SQL statement. This exploit can lead to unauthorized changes in the metadata database, compromising the integrity of authentication and authorization data. By leveraging the default examples database connection, an attacker could gain access to sensitive schema information, escalating privileges and potentially manipulating critical data without the appropriate permissions.
Affected Version(s)
Apache Superset 0 < 2.1.2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
LEXFO for Orange Innovation and Orange CERT-CC at Orange group