VulnerabilityModified
CVE-2021-44451
Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users.
MEDIUM 6.5EPSS 7.86%
Does this matter?
Lower severity and a low EPSS score (7.86%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 7.86% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- apache/superset
- Source
- security@apache.org
References
- https://lists.apache.org/thread/xww1pccs2ckb5506wrf1v4lmxg198vkbMailing List, Vendor Advisory
- https://lists.apache.org/thread/xww1pccs2ckb5506wrf1v4lmxg198vkbMailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.