Apache Superset: Lack of rate limiting allows for possible denial of service
CVE-2023-42504
6.5MEDIUM
What is CVE-2023-42504?
An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial of service.
This issue affects Apache Superset: before 3.0.0
Affected Version(s)
Apache Superset 0 < 3.0.0