CVE-2023-42504: Apache Superset: Lack of rate limiting allows for possible denial of service
An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial of service.
This issue affects Apache Superset: before 3.0.0
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-42504?
CVE-2023-42504 is a vulnerability in Apache Superset that allows an authenticated malicious user to initiate multiple concurrent requests, potentially causing a denial of service.
What is the severity of CVE-2023-42504?
The severity of CVE-2023-42504 is medium with a CVSS score of 5.8.
Which version of Apache Superset is affected by CVE-2023-42504?
Apache Superset versions before 3.0.0 are affected by CVE-2023-42504.
How can an authenticated malicious user exploit CVE-2023-42504?
An authenticated malicious user can exploit CVE-2023-42504 by initiating multiple concurrent requests, each requesting multiple dashboard exports.
Where can I find more information about CVE-2023-42504?
You can find more information about CVE-2023-42504 at the following references: [1] [2] [3]