CVE Vulnerabilities

CVE-2023-42505

Published: Nov 28, 2023 | Modified: Dec 04, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connections username.

This issue affects Apache Superset before 3.0.0.

Affected Software

Name Vendor Start Version End Version
Superset Apache * 3.0.0 (excluding)

References