CVE-2022-45438
5.3MEDIUMWhen explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint
Veröffentlicht: 1/16/2023Aktualisiert: 4/7/2025
Beschreibung
When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
KI-AnalyseKI-gestützt
Betroffene Produkte
apachesuperset
apachesuperset
2.0.0
apachesuperset
2.0.0
apachesuperset
2.0.0
Referenzen
- https://lists.apache.org/thread/snxbkf2x9kww7s0wkmydct9nhqqn9rv9Mailing ListVendor Advisory
- https://lists.apache.org/thread/snxbkf2x9kww7s0wkmydct9nhqqn9rv9Mailing ListVendor Advisory