PT-2020-13800 · Apache · Apache Superset
Published
2020-09-30
·
Updated
2025-02-05
·
CVE-2020-13952
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache Superset versions prior to 0.37.2
Description
The issue allows authenticated users running queries against Hive and Presto database engines to access sensitive information, including the contents of query description metadata database, hashed user passwords, and connection information such as plaintext passwords. Additionally, it enables users to run arbitrary methods on the database connection object, bypassing internal security controls.
Recommendations
For versions prior to 0.37.2, update to version 0.37.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the templated fields and limiting the ability to run arbitrary methods on the database connection object until a patch is applied. Restrict access to sensitive information such as query description metadata and connection details to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Superset