Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5
Описание
Apache Superset allowed for database connections password leak for authenticated users
Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-41972
- https://github.com/advisories/GHSA-42q4-9xf9-f67x
- https://github.com/apache/superset
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-superset/PYSEC-2021-434.yaml
- https://lists.apache.org/thread/xpdl2r538o695o7r9gd9qrwqb17bdd3v
- https://seclists.org/oss-sec/2021/q4/106
Пакеты
Наименование
apache-superset
pip
Затронутые версииВерсия исправления
<= 1.3.1
1.3.2
Связанные уязвимости
CVSS3: 6.5
nvd
около 4 лет назад
Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way.