imPC@ndo IT

Tracker / CVE-2023-30776

CVE-2023-30776

Medium 4.9

An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1.

Affected products and versions

apache superset · 1.3.0 → 2.0.1

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References