PT-2022-12120 · Apache · Apache Superset

Cesar Santos

·

Published

2022-02-01

·

Updated

2025-02-05

·

CVE-2021-44451

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Superset versions up to and including 1.3.2
Description The issue allows for the leak of registered database connections passwords to authenticated users. This information can be accessed in a non-trivial way.
Recommendations For Apache Superset versions up to and including 1.3.2, upgrade to Apache Superset 1.4.0 or higher.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-SUPERSET-2021-44451
CVE-2021-44451
GHSA-HHM3-48H2-597V
PYSEC-2022-36

Affected Products

Apache Superset