Описание
Apache Superset has Improper Access Control
When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Пакеты
Наименование
apache-superset
pip
Затронутые версииВерсия исправления
<= 1.5.2
Отсутствует
Наименование
apache-superset
pip
Затронутые версииВерсия исправления
= 2.0.0
Отсутствует
Связанные уязвимости
CVSS3: 5.3
nvd
около 3 лет назад
When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.