Beveiligingsadvies

CVE-2020-1932

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-01-28 00:38:15
Laatst bijgewerkt 2024-08-04 06:54:00
Toegewezen door apache
CVSS-score geen score
Status PUBLISHED

Beschrijving

An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset.