Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45694
HistoryFeb 29, 2024 - 6:56 a.m.

Incorrect Authorization

2024-02-2906:56:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
apache superset
vulnerability
access control
metadata

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%

Apache Superset is vulnerable to Incorrect Authorization. The vulnerability is due to improper access check where a low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object.

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%