cve entity

CVE-2023-27524

1 source-linked records in the current knowledge graph.

high

CVE-2023-27524: Apache Superset Insecure Default Initialization of Resource Vulnerability

Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-27524EPSS 97.4%ApacheSuperset
CISA KEV ↗ · unattributed attribution