PT-2020-13800 · Apache · Apache Superset

Published

2020-09-30

·

Updated

2025-02-05

·

CVE-2020-13952

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Superset versions prior to 0.37.2
Description The issue allows authenticated users running queries against Hive and Presto database engines to access sensitive information, including the contents of query description metadata database, hashed user passwords, and connection information such as plaintext passwords. Additionally, it enables users to run arbitrary methods on the database connection object, bypassing internal security controls.
Recommendations For versions prior to 0.37.2, update to version 0.37.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the templated fields and limiting the ability to run arbitrary methods on the database connection object until a patch is applied. Restrict access to sensitive information such as query description metadata and connection details to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BIT-SUPERSET-2020-13952
CVE-2020-13952
GHSA-77PW-C3J2-5FC8
PYSEC-2020-223

Affected Products

Apache Superset