CVE-2023-42505

MEDIUM4.3EPSS 0.04%

Apache Superset: Sensitive information disclosure on db connection details

發布日:2023/11/28修改日:2025/5/20

描述

An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

參考連結(4)