CVE-2022-45438: Apache Superset: Dashboard metadata information leak
When explicitly enabling the feature flag DASHBOARDCACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-45438?
CVE-2022-45438 is a vulnerability in Apache Superset versions 1.5.2 and prior, as well as version 2.0.0, that allows an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint when the DASHBOARD_CACHE feature flag is enabled.
How does CVE-2022-45438 affect Apache Superset?
CVE-2022-45438 affects Apache Superset versions 1.5.2 and prior, as well as version 2.0.0.
What is the severity of CVE-2022-45438?
The severity of CVE-2022-45438 is medium, with a severity value of 5.3.
How can I fix CVE-2022-45438?
To fix CVE-2022-45438, it is recommended to upgrade to a version of Apache Superset that is not affected by this vulnerability.
Where can I find more information about CVE-2022-45438?
More information about CVE-2022-45438 can be found at the following reference: [https://lists.apache.org/thread/snxbkf2x9kww7s0wkmydct9nhqqn9rv9]