oss-sec mailing list archives

CVE-2023-27526: Apache Superset: Improper Authorization check on import charts


From: Daniel Gaspar <dpgaspar () apache org>
Date: Wed, 06 Sep 2023 09:21:13 +0000

Affected versions:

- Apache Superset through 2.1.0

Description:

A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset 
up to and including 2.1.0.

Credit:

NTT DATA (finder)

References:

https://superset.apache.org
https://www.cve.org/CVERecord?id=CVE-2023-27526


Current thread: