CVE-2023-36387: Apache Superset: Improper API permission for low privilege users
Published Sep 6, 2023
·Updated
An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.
Affected Software
2 affected components
pip/apache-superset<=2.1.0
Apache Superset<=2.1.0
Remediation
Patch Available
Event History
Sep 6, 2023
CVE Published
via MITRE·12:19 PM
Data Sourced
via MITRE·12:19 PM
DescriptionSeverityWeakness
Advisory Published
03:30 PM
Frequently Asked Questions
1
What is CVE-2023-36387?
CVE-2023-36387 is a vulnerability in Apache Superset that allows authenticated Gamma users to test database connections.
2
How does CVE-2023-36387 affect Apache Superset?
CVE-2023-36387 affects Apache Superset up to and including version 2.1.0.
3
What is the severity of CVE-2023-36387?
CVE-2023-36387 has a severity rating of medium (5.4).
4
How can I fix CVE-2023-36387?
To fix CVE-2023-36387, it is recommended to upgrade Apache Superset to a version higher than 2.1.0.
5
Where can I find more information about CVE-2023-36387?
You can find more information about CVE-2023-36387 on the Apache Superset website, the NVD website, and the GitHub advisory page.