Jan. 16, 2023, 11:15 a.m. |

National Vulnerability Database web.nvd.nist.gov

When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.

access apache apache superset api configuration cve dashboard default disabled endpoint flag issue metadata rest rest api superset system version version 1

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Security Officer Hospital Mission Viejo

@ Allied Universal | Mission Viejo, CA, United States

Junior Offensive Cyber Security Researcher

@ Draper | Cambridge, MA, United States

Consultant reporting reglementaire

@ Talan | Luxembourg, Luxembourg

Chief Information Security Officer

@ Kantox | Barcelona, Catalonia, Spain