Lucene search

K
githubGitHub Advisory DatabaseGHSA-VV65-FJFJ-4736
HistoryNov 27, 2023 - 12:30 p.m.

Apache Superset has Incorrect Default Permissions

2023-11-2712:30:55
CWE-276
GitHub Advisory Database
github.com
11
apache superset
default permissions
vulnerability
upgrade
css templates
annotations

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

48.1%

Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations.
This issue affects Apache Superset: before 2.1.2.
Users should upgrade to version or above 2.1.2 and run superset init to reconstruct the Gamma role or remove can_read permission from the mentioned resources.

Affected configurations

Vulners
Node
apachesupersetRange<2.1.2
VendorProductVersionCPE
apachesuperset*cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

48.1%

Related for GHSA-VV65-FJFJ-4736