CVE-2023-42505

An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*

History

13 Feb 2025, 17:17

Type Values Removed Values Added
Summary (en) An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0. (en) An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0.

Information

Published : 2023-11-28 17:15

Updated : 2025-02-13 17:17


NVD link : CVE-2023-42505

Mitre link : CVE-2023-42505

CVE.ORG link : CVE-2023-42505


JSON object : View

Products Affected

apache

  • superset
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo