An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://lists.apache.org/thread/s9w9w10mt2sngk3solwnmq5k7md53tsz | vendor advisory mailing list |
http://www.openwall.com/lists/oss-security/2023/04/24/3 | third party advisory mailing list |