CVE-2023-27524: Apache Superset's Authentication Bypass and RCE

แชร์
ฝัง
  • เผยแพร่เมื่อ 7 ก.ย. 2023
  • PoC for CVE-2023-27524: Apache Superset's Authentication Bypass and RCE.
    Apache Superset versions up to and including 2.0.1 are susceptible to a critical session validation vulnerability. Installations that have not modified the default SECRET_KEY configuration as per installation instructions are at risk. Attackers can exploit this vulnerability to authenticate and gain access to unauthorized resources. Superset administrators who have changed the default SECRET_KEY value are not affected by this vulnerability.
    This video PoC was created for a CVE analysis www.vicarius.io/vsociety
    Repo:github.com/jak...

ความคิดเห็น •