U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2023-27524

Change History

CVE Modified by Apache Software Foundation 4/08/2024 5:15:07 AM

Action Type Old Value New Value
Changed Description
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config.
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config.

All superset installations should always set a unique secure random SECRET_KEY. Your SECRET_KEY is used to securely sign all session cookies and encrypting sensitive information on the database.
Add a strong SECRET_KEY to your `superset_config.py` file like:

SECRET_KEY = <YOUR_OWN_RANDOM_GENERATED_SECRET_KEY>

Alternatively you can set it with `SUPERSET_SECRET_KEY` environment variable.
Added Reference

								
							
							
						
Apache Software Foundation https://packetstormsecurity.com/files/172522/Apache-Superset-2.0.0-Authentication-Bypass.html [No types assigned]
Added Reference

								
							
							
						
Apache Software Foundation https://packetstormsecurity.com/files/175094/Apache-Superset-2.0.0-Remote-Code-Execution.html [No types assigned]
Added Reference

								
							
							
						
Apache Software Foundation https://www.openwall.com/lists/oss-security/2023/04/24/2 [No types assigned]
Removed Reference
Apache Software Foundation http://packetstormsecurity.com/files/172522/Apache-Superset-2.0.0-Authentication-Bypass.html

								
						
Removed Reference
Apache Software Foundation http://packetstormsecurity.com/files/175094/Apache-Superset-2.0.0-Remote-Code-Execution.html

								
						
Removed Reference
Apache Software Foundation http://www.openwall.com/lists/oss-security/2023/04/24/2