CVE-2023-25504
Apache Superset Server-Side Request Forgery vulnerability
6.5
MEDIUM
CVSS 3.1
EPSS 0.16%
Description
A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery attacks and query internal resources on behalf of the server where Superset is deployed. This vulnerability exists in Apache Superset versions up to and including 2.0.1.
How to fix CVE-2023-25504
To remediate CVE-2023-25504, upgrade the affected package to a fixed version below.
- —upgrade to 2.0.2 or later
- —upgrade to 2.1.0 or later
Is CVE-2023-25504 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.0.2
- from 0, < 2.1.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |