CVE-2023-27524 is a critical session validation vulnerability affecting Apache Superset versions up to and including 2.0.1. Installations that have not changed the default SECRET_KEY are susceptible, allowing attackers to authenticate and access unauthorized resources. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, with public exploit code available in Metasploit, Nuclei templates, and ExploitDB, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.1CPE matchmatch criteria | cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:* | ||
>= 0, <= 2.0.1CPE match | cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.