CVE-2023-36388

MEDIUM4.3EPSS 0.13%

Apache Superset: Improper API permission for low privilege users allows for SSRF

Published: 9/6/2023Modified: 5/20/2025

Description

Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possible SSRF.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References (3)