Sploitus

CVE-2023-40610

No indexed exploits for CVE-2023-40610 yet

Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database connection that allows access to both the examples schema and Apache Superset's metadata database, an attacker using a specially crafted CTE SQL statement could change data on the metadata database. This weakness could result on tampering with the authentication/authorization data.

Affected products
Apache Superset
Apache Superset
< 2.1.2
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
1.3% (69th percentile)
Weakness
CWE-863
NVD status
Modified
Published
2023-11-27
CVE-2023-40610 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-40610 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-40610 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.