VulnerabilityModified
CVE-2021-41972
Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users.
MEDIUM 6.5EPSS 1.50%
Does this matter?
Lower severity and a low EPSS score (1.50%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.50% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- apache/superset
- Source
- security@apache.org
References
- https://lists.apache.org/thread/xpdl2r538o695o7r9gd9qrwqb17bdd3vMailing List, Vendor Advisory
- https://seclists.org/oss-sec/2021/q4/106Mailing List, Third Party Advisory
- https://lists.apache.org/thread/xpdl2r538o695o7r9gd9qrwqb17bdd3vMailing List, Vendor Advisory
- https://seclists.org/oss-sec/2021/q4/106Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.