VulnerabilityModified
CVE-2023-42505
An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username.
MEDIUM 4.3EPSS 1.02%
Does this matter?
Lower severity and a low EPSS score (1.02%). Track it; it rarely justifies an emergency change on its own.
Description
An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.02% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apache/superset
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2023/11/28/5Mailing List, Third Party Advisory
- https://lists.apache.org/thread/bd0fhtfzrtgo1q8x35tpm8ms144d1t2yMailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/11/28/5Mailing List, Third Party Advisory
- https://lists.apache.org/thread/bd0fhtfzrtgo1q8x35tpm8ms144d1t2yMailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.