PT-2022-12120 · Apache · Apache Superset
Cesar Santos
·
Published
2022-02-01
·
Updated
2025-02-05
·
CVE-2021-44451
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache Superset versions up to and including 1.3.2
Description
The issue allows for the leak of registered database connections passwords to authenticated users. This information can be accessed in a non-trivial way.
Recommendations
For Apache Superset versions up to and including 1.3.2, upgrade to Apache Superset 1.4.0 or higher.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Superset