Sploitus

CVE-2023-25504

No indexed exploits for CVE-2023-25504 yet

A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery attacks and query internal resources on behalf of the server where Superset is deployed. This vulnerability exists in Apache Superset versions up to and including 2.0.1.

Affected products
Apache Superset
Apache Superset
≤ 2.0.1
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
1.0% (59th percentile)
Weakness
CWE-918
NVD status
Modified
Published
2023-04-17
CVE-2023-25504 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-25504 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-25504 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.