EXPOSURES › CVE-2023-27524
CVE-2023-27524
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Superset shipped with a default SECRET_KEY that allows attackers to authenticate and access unauthorized resources without changing configuration.
Apache Superset defaults to an insecure SECRET_KEY, enabling attackers to bypass authentication and access unauthorized data on unpatched installations. DIB orgs must verify vendor defaults and enforce configuration hardening to prevent unauthorized data access and potential compliance violations.
Shame score — Apache Superset shipped with a default SECRET_KEY that allows attackers to bypass authentication and access unauthorized data on unpatched installations.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions.