← voltar
CVE-2023-27524highsob ataqueCWE-1188

Apache Superset: Session validation vulnerability when using provided default SECRET_KEY

100Vexday Risk Score

Corrija agora. Ela está sob exploração confirmada pelo CISA e tem exploit funcional público.

ssvc Actcvss 8.9epss 97%
da publicação à arma1 dias
Publicada no NVD24 de abr.
1ª PoC+1d
metasploit+1d
CISA KEV+259d
probabilidade de exploração
97%top 1% das CVEs
exploração observada
simCISA + VulnCheck
29 exploit(s) público(s)
Ação exigida pela CISAprazo federal: 2024-01-29

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Versões

Afetadas
>= 0
Pesquisado e redigido com IA a partir do advisory do fornecedor e de análises públicas, com as fontes acima. Confira sempre a versão corrigida no advisory oficial antes de agir.
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config. All superset installations should always set a unique secure random SECRET_KEY. Your SECRET_KEY is used to securely sign all session cookies and encrypting sensitive information on the database. Add a strong SECRET_KEY to your `superset_config.py` file like: SECRET_KEY = <YOUR_OWN_RANDOM_GENERATED_SECRET_KEY> Alternatively you can set it with `SUPERSET_SECRET_KEY` environment variable.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
PoCs públicas encontradas29
exploitdbwww.exploit-db.com/exploits/51447não verificadogithubgithub.com/horizon3ai/CVE-2023-27524112githubgithub.com/jakabakos/CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE28githubgithub.com/tardc/CVE-2023-2752411githubgithub.com/Okaytc/Superset_auth_bypass_check11githubgithub.com/Ap0dexMe0/CVE-2023-275243githubgithub.com/ZZ-SOCMAP/CVE-2023-275243githubgithub.com/Cappricio-Securities/CVE-2023-275242githubgithub.com/karthi-the-hacker/CVE-2023-275241githubgithub.com/sumaiyafathima-code/CVE-2023-275240githubgithub.com/h1n4mx0/Research-CVE-2023-275240githubgithub.com/MaanVader/CVE-2023-27524-POC0githubgithub.com/necroteddy/CVE-2023-275240githubgithub.com/CN016/Apache-Superset-SECRET_KEY-CVE-2023-27524-0githubgithub.com/h1n4mx0z/Research-CVE-2023-275240githubgithub.com/rachidafaf/bola-CVE-2023-275240vulncheckvulncheck.com/xdb/d258b47e2ea9não verificadocve_referencepacketstormsecurity.com/files/175094/Apache-Superset-2.0.0-Remote-Code-Execution.htmlnão verificadovulncheckvulncheck.com/xdb/925cc8f34b1dnão verificadovulncheckvulncheck.com/xdb/a4304932f8c7não verificadovulncheckvulncheck.com/xdb/3f3b3474bcd8não verificadovulncheckvulncheck.com/xdb/3a6a4fb601a4não verificadovulncheckvulncheck.com/xdb/96ea12e77e80não verificadovulncheckvulncheck.com/xdb/a2f39ee2e959não verificadovulncheckvulncheck.com/xdb/4abf848aca22não verificadovulncheckvulncheck.com/xdb/49026b01a9e8não verificadovulncheckvulncheck.com/xdb/d23c099d5d89não verificadovulncheckvulncheck.com/xdb/7b3694a59dccnão verificadocve_referencepacketstormsecurity.com/files/172522/Apache-Superset-2.0.0-Authentication-Bypass.htmlnão verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.