VulnerabilityModified
CVE-2023-27525
An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1
MEDIUM 4.3EPSS 0.78%
Does this matter?
Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.
Description
An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- apache/superset
- Source
- security@apache.org
References
- https://lists.apache.org/thread/wpv7b17zjg2pmvpfkdd6nn8sco8y2q77Mailing List, Vendor Advisory
- https://lists.apache.org/thread/wpv7b17zjg2pmvpfkdd6nn8sco8y2q77Mailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.