cve/2022/CVE-2022-45438.md
2024-05-25 21:48:12 +02:00

818 B

CVE-2022-45438

Description

When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.

POC

Reference

No PoCs from references.

Github