cve/2023/CVE-2023-42501.md
2024-05-25 21:48:12 +02:00

860 B

CVE-2023-42501

Description

Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations.This issue affects Apache Superset: before 2.1.2.Users should upgrade to version or above 2.1.2 and run superset init to reconstruct the Gamma role or remove can_read permission from the mentioned resources.

POC

Reference

No PoCs from references.

Github