CVE Published: 28/11/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Superset Status : PUBLISHED
CVE-2023-42505 Description
An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection\'s username.
This issue affects Apache Superset before 3.0.0.
Metrics
CVSS Version: 3.1 |
Base Score: 4.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N