Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fgpw-4w69-j256

Опубликовано: 28 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability

An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username.

This issue affects Apache Superset before 3.0.0.

Пакеты

Наименование

apache-superset

pip
Затронутые версииВерсия исправления

< 3.0.0

3.0.0

EPSS

Процентиль: 13%
0.00044
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 лет назад

An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0.

EPSS

Процентиль: 13%
0.00044
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200