Home > Cyber News > CVE-2023-27524: Vulnerability in Apache Superset Software
CYBER NEWS

CVE-2023-27524: Vulnerability in Apache Superset Software

Maintainers of the Apache Superset open source data visualization software have issued updates to address a security vulnerability, tracked as CVE-2023-27524, with a CVSS score of 8.9.

This vulnerability, which is present in versions 2.0.1 and prior, is caused by an insecure default configuration that could result in remote code execution. By exploiting the default SECRET_KEY, malicious actors could gain access to unauthorized resources on internet-exposed installations of the software.

CVE-2023-27524- Vulnerability in Apache Superset Software

CVE-2023-27524 Technical Overview

According to the official National Vulnerability Database description, “Session Validation attacks in Apache Superset versions up to and including 2.0.1” are possible. If the installation has followed instructions and changed the default value for the SECRET_KEY config, then the unauthorized access of resources by attackers is prevented. However, installations that have not modified the default configured SECRET_KEY may be vulnerable to this type of attack.




Naveen Sunkavally, security researcher at Horizon3.ai, characterized the issue as a perilous default setup in Apache Superset that permits an unauthorized attacker to get remote code execution, accumulate qualifications, and endanger data. It should be noted that the bug does not impact Superset situations that have changed the default value for the SECRET_KEY config to a more cryptographically reliable arbitrary string.

Further technical details are available in the original report.

Milena Dimitrova

An inspired writer and content manager who has been with SensorsTechForum since the project started. A professional with 10+ years of experience in creating engaging content. Focused on user privacy and malware development, she strongly believes in a world where cybersecurity plays a central role. If common sense makes no sense, she will be there to take notes. Those notes may later turn into articles! Follow Milena @Milenyim

More Posts

Follow Me:
Twitter

Leave a Comment

Your email address will not be published. Required fields are marked *

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.
I Agree