Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40370
HistoryMay 01, 2023 - 11:21 p.m.

Authentication Bypass

2023-05-0123:21:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
24
apache_superset
vulnerability
default secret key
authentication
bypass
installation instructions

EPSS

0.971

Percentile

99.8%

apache_superset is vulnerable to Authentication Bypass. The vulnerability is due to a default secret key in which allows an attacker to authenticate and access unauthorized resources when the default configuration of SECRET_KEY is not altered according to the installation instructions.