CVE-2023-27525
MEDIUMCVSS 4.3/10EPSS 0.77%
Last modified
CVE-2023-27525 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1 . EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Superset | <= 2.0.1 |
References
- https://lists.apache.org/thread/wpv7b17zjg2pmvpfkdd6nn8sco8y2q77Mailing List, Vendor Advisory
- https://lists.apache.org/thread/wpv7b17zjg2pmvpfkdd6nn8sco8y2q77Mailing List, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-27525?
An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1
How severe is CVE-2023-27525?
CVE-2023-27525 has a CVSS score of 4.3/10 (MEDIUM severity). The EPSS model estimates a 0.77% probability of exploitation in the next 30 days.
How do I fix CVE-2023-27525?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-2752Cross-site Scripting (XSS) - Stored in GitHub repository tho…5.4
- CVE-2023-27520Cross-site request forgery (CSRF) vulnerability in SEIKO EPS…6.5
- CVE-2023-27521OS command injection vulnerability in the mail setting page …8.8
- CVE-2023-27522HTTP Response Smuggling vulnerability in Apache HTTP Server …7.5
- CVE-2023-27523Improper data authorization check on Jinja templated queries…4.3
- CVE-2023-27524Session Validation attacks in Apache Superset versions up to…9.8
- CVE-2023-27526A non Admin authenticated user could incorrectly create reso…4.3
- CVE-2023-27527Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts …7.5
- CVE-2023-27529Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) c…7.8
- CVE-2023-2753Cross-site Scripting (XSS) - Stored in GitHub repository tho…5.4
- CVE-2023-27530A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2…7.5
- CVE-2023-27531There is a deserialization of untrusted data vulnerability i…5.3
Are you affected by CVE-2023-27525?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
