Vulnerability CVE-2023-25504


Published: 2023-04-17

Description:
A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery
attacks and query internal resources on behalf of the server where Superset
is deployed. This vulnerability exists in Apache Superset versions up to and including 2.0.1.

Type:

CWE-918

 References:
https://lists.apache.org/thread/tdnzkocfsqg2sbbornnp9g492fn4zhtx

Copyright 2026, cxsecurity.com

 

Back to Top