First published: Tue Nov 28 2023(Updated: )
An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/apache-superset | <3.0.0 | 3.0.0 |
Apache Superset | <3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42505 is a vulnerability in Apache Superset that allows an authenticated user to access sensitive information, such as a database connection's username.
CVE-2023-42505 affects Apache Superset versions before 3.0.0.
The severity of CVE-2023-42505 is medium, with a CVSS score of 4.3.
An attacker can exploit CVE-2023-42505 by being an authenticated user with read permissions on database connections metadata.
To fix CVE-2023-42505, update Apache Superset to version 3.0.0 or later.