Apache Superset: Privilege Escalation Vulnerability
CVE-2023-49734
7.7HIGH
Summary
An authenticated user in Apache Superset can create a dashboard and inadvertently gain ownership of the associated charts, allowing unauthorized write access to these charts. This issue arises in versions prior to 2.1.2 and from 3.0.0 before 3.0.2, posing a risk to data integrity. Users are advised to upgrade to versions 3.0.2 or 2.1.3 to mitigate this issue.
Affected Version(s)
Apache Superset 0 < 2.1.2
Apache Superset 3.0.0 < 3.0.2
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jordan Velich