First published: Mon Apr 24 2023(Updated: )
An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Superset | >=1.3.0<=2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30776 is a vulnerability in Apache Superset that allows an authenticated user with specific data permissions to access the stored passwords of database connections.
No, CVE-2023-30776 has a severity value of 6.5 which is considered medium.
CVE-2023-30776 affects Apache Superset versions 1.3.0 up to 2.0.1.
An attacker with specific data permissions can exploit CVE-2023-30776 by making a request to a specific REST API in Apache Superset.
Yes, upgrading to Apache Superset version 2.0.2 or higher will fix the vulnerability.