CVE-2024-23952: Apache Superset: Allows for uncontrolled resource consumption via a ZIP bomb (version range fix for CVE-2023-46104)
Duplicate Advisory This advisory has been withdrawn because it is a duplicate of CVE-2023-46104. This link is maintained to preserve external references.
Original Description With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets. This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.
Other sources
This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets. This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/apache-supersetto a version that resolves this vulnerability.Fixed in 3.0.1 - Upgrade
Upgrade
pip/apache-supersetto a version that resolves this vulnerability.Fixed in 2.1.2 - Upgrade
Upgrade
Apache Supersetto a version that resolves this vulnerability.Fixed in 2.1.2Patch CVE-2023-46104 - Upgrade
Upgrade
Apache Supersetto a version that resolves this vulnerability.Fixed in 3.0.1Patch CVE-2023-46104
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23952?
The severity of CVE-2024-23952 is considered moderate due to its potential for uncontrolled resource consumption.
How do I fix CVE-2024-23952?
To mitigate CVE-2024-23952, upgrade Apache Superset to version 3.0.2 or above if on version 3.0.1, or to 2.1.2 or later if using version 2.1.2.
What versions of Apache Superset are affected by CVE-2024-23952?
CVE-2024-23952 affects Apache Superset versions up to 3.0.1 and prior versions up to 2.1.2.
Is CVE-2024-23952 a duplicate vulnerability?
Yes, CVE-2024-23952 has been withdrawn as it is a duplicate of CVE-2023-46104.
What should I do if I am using an affected version of Apache Superset related to CVE-2024-23952?
If using an affected version, immediately upgrade to the latest recommended version to ensure security.