CVE Vulnerabilities

CVE-2020-1932

Published: Jan 28, 2020 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset.

Affected Software

NameVendorStart VersionEnd Version
SupersetApache0.34.0 (including)0.34.0 (including)
SupersetApache0.34.1 (including)0.34.1 (including)
SupersetApache0.35.0 (including)0.35.0 (including)
SupersetApache0.35.1 (including)0.35.1 (including)

References