Apache Superset: Privilege escalation with default examples database
CVE-2023-40610
6.3MEDIUM
What is CVE-2023-40610?
A vulnerability exists in Apache Superset versions up to but not including 2.1.2, where improper authorization checks can allow an attacker to exploit a specially crafted CTE SQL statement. This exploit can lead to unauthorized changes in the metadata database, compromising the integrity of authentication and authorization data. By leveraging the default examples database connection, an attacker could gain access to sensitive schema information, escalating privileges and potentially manipulating critical data without the appropriate permissions.
Affected Version(s)
Apache Superset 0 < 2.1.2
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
LEXFO for Orange Innovation and Orange CERT-CC at Orange group