CVE-2023-40610
Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database connection that allows access to both the examples schema and Apache Superset's metadata database, an attacker using a specially crafted CTE SQL statement could change data on the metadata database. This weakness could result on tampering with the authentication/authorization data.
- Affected products
- Apache Superset
- Apache Superset
- < 2.1.2
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.3% (69th percentile)
- Weakness
- CWE-863
- NVD status
- Modified
- Published
- 2023-11-27
CVE-2023-40610 at NVD
No indexed exploits for CVE-2023-40610 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-40610 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.