Lucene search

K
osvGoogleOSV:GHSA-HHM3-48H2-597V
HistoryFeb 02, 2022 - 12:01 a.m.

Insufficiently Protected Credentials in Apache Superset

2022-02-0200:01:46
Google
osv.dev
15
apache superset
password leak
registered database connections
upgrade

EPSS

0.006

Percentile

78.6%

Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher.

EPSS

0.006

Percentile

78.6%