Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45686
HistoryFeb 29, 2024 - 5:31 a.m.

Improper Authorization

2024-02-2905:31:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
apache-superset
improper authorization
custom roles
virtual datasets
unauthorized data

CVSS3

5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%

apache-superset is vulnerable to Improper Authorization. The vulnerability is due to a user with custom roles that include can write on dataset which allows them to create virtual datasets to data they don’t have access to. These users could then use those virtual datasets to get access to unauthorized data.

CVSS3

5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%