CVE-2023-27525

LOW

Apache Superset <= 2.0.1 - Authenticated Metadata Exposure via Non-Trivial Methods

Title source: llm
STIX 2.1

Description

An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1

References (1)

Core 1
Core References
Mailing List, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/wpv7b17zjg2pmvpfkdd6nn8sco8y2q77

Scores

CVSS v3 3.1
EPSS 0.0053
EPSS Percentile 67.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
apache/superset < 2.0.1
pypi/apache-superset 0PyPI
Published Apr 17, 2023
Tracked Since Feb 18, 2026