SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-42501

Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations.

MEDIUM 4.3EPSS 0.86%

Does this matter?

Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.

Description

Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations. This issue affects Apache Superset: before 2.1.2. Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma role or remove `can_read` permission from the mentioned resources.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.86% probability · 56th percentile
CISA KEV
Not listed
Weakness
CWE-276
Affected
apache/superset
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.