Vulnerability Description
An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Superset | < 3.0.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2023/11/28/5Mailing ListThird Party Advisory
- https://lists.apache.org/thread/bd0fhtfzrtgo1q8x35tpm8ms144d1t2yMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/11/28/5Mailing ListThird Party Advisory
- https://lists.apache.org/thread/bd0fhtfzrtgo1q8x35tpm8ms144d1t2yMailing ListThird Party Advisory
FAQ
What is CVE-2023-42505?
CVE-2023-42505 is a vulnerability with a CVSS score of 4.3 (MEDIUM). An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset befor...
How severe is CVE-2023-42505?
CVE-2023-42505 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-42505?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Superset.