Apache superset missing check for default SECRET_KEY
High severity
GitHub Reviewed
Published
Apr 24, 2023
to the GitHub Advisory Database
•
Updated Apr 8, 2024
Description
Published by the National Vulnerability Database
Apr 24, 2023
Published to the GitHub Advisory Database
Apr 24, 2023
Reviewed
Apr 24, 2023
Last updated
Apr 8, 2024
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config.
References