CVE Vulnerabilities

CVE-2020-1932

Published: Jan 28, 2020 | Modified: Jul 21, 2021
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset.

Affected Software

Name Vendor Start Version End Version
Superset Apache 0.34.0 (including) 0.34.0 (including)
Superset Apache 0.34.1 (including) 0.34.1 (including)
Superset Apache 0.35.0 (including) 0.35.0 (including)
Superset Apache 0.35.1 (including) 0.35.1 (including)

References