CVE-2023-46104

MEDIUM6.5EPSS 0.59%

Apache Superset uncontrolled resource consumption

Published: 12/19/2023Modified: 2/13/2025
Also known as:GHSA-95mg-jgfx-54v9BIT-superset-2023-46104

Description

Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.   This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

References (8)