Lucene search

K
nessusThis script is Copyright (C) 2024 and is owned by Tenable, Inc. or an Affiliate thereof.APACHE_SUPERSET_KNOWN_SECRET_KEY.NBIN
HistoryMay 16, 2024 - 12:00 a.m.

Apache Superset Known Default SECRET_KEY (CVE-2023-27524)

2024-05-1600:00:00
This script is Copyright (C) 2024 and is owned by Tenable, Inc. or an Affiliate thereof.
www.tenable.com
15
apache superset
secret key
vulnerability
scanner

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

Low

EPSS

0.971

Percentile

99.8%

The Apache Superset install on the remote host is configured to use a known default SECRET_KEY. This can allow a remote, unauthenticated attacker to forge session cookies as arbitrary users, bypassing authentication and leading to remote code execution.

Binary data apache_superset_known_secret_key.nbin

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

Low

EPSS

0.971

Percentile

99.8%