oss-sec mailing list archives
CVE-2022-45438: Apache Superset: Dashboard metadata information leak
From: Daniel Gaspar <dpgaspar () apache org>
Date: Mon, 16 Jan 2023 09:31:37 +0000
Description: When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0. Credit: Sunny Alexli (finder) References: https://superset.apache.org https://www.cve.org/CVERecord?id=CVE-2022-45438
Current thread:
- CVE-2022-45438: Apache Superset: Dashboard metadata information leak Daniel Gaspar (Jan 16)