Vulnerability Description
Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Superset | <= 1.3.2 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/xww1pccs2ckb5506wrf1v4lmxg198vkbMailing ListVendor Advisory
- https://lists.apache.org/thread/xww1pccs2ckb5506wrf1v4lmxg198vkbMailing ListVendor Advisory
FAQ
What is CVE-2021-44451?
CVE-2021-44451 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgra...
How severe is CVE-2021-44451?
CVE-2021-44451 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44451?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Superset.