Skip to content
COOEY

EXPOSURES › CVE-2023-27524

CVE-2023-27524

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-01-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-27524 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wilddefault-credsdata-breachunpatched

Apache Superset shipped with a default SECRET_KEY that allows attackers to authenticate and access unauthorized resources without changing configuration.

Apache Superset defaults to an insecure SECRET_KEY, enabling attackers to bypass authentication and access unauthorized data on unpatched installations. DIB orgs must verify vendor defaults and enforce configuration hardening to prevent unauthorized data access and potential compliance violations.

Shame score — Apache Superset shipped with a default SECRET_KEY that allows attackers to bypass authentication and access unauthorized data on unpatched installations.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.