SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-25504

A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery attacks and query internal resources on behalf of the server where…

MEDIUM 6.5EPSS 0.96%

Does this matter?

Lower severity and a low EPSS score (0.96%). Track it; it rarely justifies an emergency change on its own.

Description

A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery attacks and query internal resources on behalf of the server where Superset is deployed. This vulnerability exists in Apache Superset versions up to and including 2.0.1.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.96% probability · 59th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
apache/superset
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.