Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way.
Workaround:
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://lists.apache.org/thread/xpdl2r538o695o7r9gd9qrwqb17bdd3v | vendor advisory mailing list |
https://seclists.org/oss-sec/2021/q4/106 | third party advisory mailing list |