Vulnerability Description
Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Superset | <= 1.3.1 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/xpdl2r538o695o7r9gd9qrwqb17bdd3vMailing ListVendor Advisory
- https://seclists.org/oss-sec/2021/q4/106Mailing ListThird Party Advisory
- https://lists.apache.org/thread/xpdl2r538o695o7r9gd9qrwqb17bdd3vMailing ListVendor Advisory
- https://seclists.org/oss-sec/2021/q4/106Mailing ListThird Party Advisory
FAQ
What is CVE-2021-41972?
CVE-2021-41972 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way.
How severe is CVE-2021-41972?
CVE-2021-41972 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-41972?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Superset.