← volver
CVE-2025-27696

Apache Superset: Incorrect authorization leading to resource ownership takeover

CVSS 5.3 MEDIUMEPSS 1.0%CWE-863
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
13 may 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade to version 4.1.2 or above, which fixes the issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →