Rewterz
Rewterz Threat Alert – Remcos RAT – Active IOCs
November 28, 2023
Rewterz
Rewterz Threat Advisory – Multiple Adobe Photoshop Vulnerabilities
November 28, 2023

Rewterz Threat Advisory – Multiple Apache Superset Vulnerabilities

Severity

High

Analysis Summary

CVE-2023-40610 CVSS:8.8

Apache Superset could allow a remote authenticated attacker to gain elevated privileges on the system, caused by improper authorization validation. By sending a specially crafted request using the default examples database connection, an authenticated attacker could exploit this vulnerability to gain elevated privileges to access to both the examples schema and Superset’s metadata database.

CVE-2023-42501 CVSS:6.5

Apache Superset could allow a remote authenticated attacker to obtain sensitive information, caused by an unnecessary read permissions flaw within the Gamma role. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.

CVE-2023-43701 CVSS:6.4

Apache Superset is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

Impact

  • Privileges Escalation
  • Information Disclosure
  • Cross-Site Scripting

Indicators Of Compromise

CVE

  • CVE-2023-40610
  • CVE-2023-42501
  • CVE-2023-43701

Affected Vendors

Apache

Affected Products

  • Apache Superset 2.1.1

Remediation

Upgrade to the latest version of Apache Superset, available from the Apache Web site.

Apache Web site