Affected versions:

- Apache Superset through 2.1.0

Description:

Improper REST API permission in Apache Superset up to and including 2.1.0 
allows for an authenticated Gamma users to test network connections, possible 
SSRF.

Credit:

https://github.com/vin01 (finder)

References:

https://superset.apache.org
https://www.cve.org/CVERecord?id=CVE-2023-36388

Reply via email to