Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-27524
HistoryApr 24, 2023 - 4:15 p.m.

Design/Logic Flaw

2023-04-2416:15:00
PRIOn knowledge base
www.prio-n.com
9
design flaw
logic flaw
session validation
apache superset
unauthorized access

9.2 High

AI Score

Confidence

High

0.97 High

EPSS

Percentile

99.8%

Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config.

CPENameOperatorVersion
supersetle2.0.1