Sploitus

CVE-2023-27524

36 known exploits for CVE-2023-27524

Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config. All superset installations should always set a unique secure random SECRET_KEY. Your SECRET_KEY is used to securely sign all session cookies and encrypting sensitive information on the database. Add a strong SECRET_KEY to your `superset_config.py` file like: SECRET_KEY = <YOUR_OWN_RANDOM_GENERATED_SECRET_KEY> Alternatively you can set it with `SUPERSET_SECRET_KEY` environment variable.

Affected products
Apache Superset
Apache Superset
≤ 2.0.1
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
97.4% (100th percentile)
Weakness
CWE-1188
NVD status
Analyzed
Published
2023-04-24
CVE-2023-27524 at NVD
Authoritative description, scoring and affected products

36 known exploits for CVE-2023-27524

Proof-of-concept code and exploit modules indexed by Sploitus

sound4-directory-listing
2026-09-10 KitPloitKITPLOIT
cgi-printenv
2026-09-10 KitPloitKITPLOIT
aem-xss
2026-09-10 KitPloitKITPLOIT
Superset_auth_bypass_check
2026-09-10 KitPloitKITPLOIT
CVE-2023-27524
2026-09-10 KitPloitKITPLOIT
CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE
2026-09-10 KitPloitKITPLOIT
CVE-2023-27524
2026-09-10 KitPloitKITPLOIT
CVE-2023-27524
2026-09-10 KitPloitKITPLOIT
Research-CVE-2023-27524
2026-09-09 KitPloitKITPLOIT
CVE-2023-27524
2026-09-08 KitPloitKITPLOIT
CVE-2023-27524
2026-09-07 KitPloitKITPLOIT
CVE-2023-27524
2026-09-07 KitPloitKITPLOIT
bola-CVE-2023-27524
2026-09-06 KitPloitKITPLOIT
CVE-2023-27524
2026-09-06 KitPloitKITPLOIT
CVE-2023-27524
2026-09-06 KitPloitKITPLOIT
CVE-2023-27524-POC
2026-09-05 KitPloitKITPLOIT
Apache-Superset-SECRET_KEY-CVE-2023-27524-
2026-09-05 KitPloitKITPLOIT
Apache Superset Signed Cookie Privilege Escalation
2024-08-31 h00die, Spencer McIntyre, Naveen Sunkavally, paradoxis, metasploit.comPACKETSTORMRuby
Exploit for Path Traversal in Oracle Weblogic_Server
2024-06-05 Cappricio-SecuritiesGITHUB
Exploit for Missing Authorization in Myeventon Eventon
2024-06-03 Cappricio-SecuritiesGITHUB
Exploit for Insecure Default Initialization of Resource in Apache Superset
2024-05-11 Cappricio-SecuritiesGITHUB
Exploit for Cross-site Scripting in Phpmyfaq
2024-05-11 Cappricio-SecuritiesGITHUB
Apache Superset 2.0.0 Remote Code Execution Exploit
2023-10-15 metasploitZDTRuby
Apache Superset 2.0.0 Remote Code Execution
2023-10-13 h00die, Spencer McIntyre, Naveen Sunkavally, paradoxis, metasploit.comPACKETSTORMRuby
Exploit for Insecure Default Initialization of Resource in Apache Superset
2023-09-08 jakabakosGITHUB
Apache Superset 2.0.0 Authentication Bypass
2023-05-24 MaanVaderPACKETSTORMPython
Apache Superset 2.0.0 - Authentication Bypass Exploit
2023-05-23 MaanVaderZDTPython
Apache Superset 2.0.0 - Authentication Bypass
2023-05-23 MaanVaderEXPLOITDBPython
Exploit for Insecure Default Initialization of Resource in Apache Superset
2023-05-04 MaanVaderGITHUB
Exploit for Insecure Default Initialization of Resource in Apache Superset
2023-05-04 ThatNotEasyGITHUB
Exploit for Insecure Default Initialization of Resource in Apache Superset
2023-05-04 Pari-MalamGITHUB
Exploit for Insecure Default Initialization of Resource in Apache Superset
2023-04-27 antx-codeGITHUB
Exploit for Insecure Default Initialization of Resource in Apache Superset
2023-04-27 ZZ-SOCMAPGITHUB
Apache Superset Signed Cookie Priv Esc
2023-04-25 h00die, paradoxis, Spencer McIntyre, Naveen SunkavallyMETASPLOITRuby
Exploit for Insecure Default Initialization of Resource in Apache Superset
2023-04-25 horizon3aiGITHUB
CVE-2023-27524
2023-04-24 apacheUNKNOWN