← back
CVE-2023-36388mediumCWE-918

Apache Superset: Improper API permission for low privilege users allows for SSRF

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.3epss 1.1%
exploitation probability
1.1%top 35% of all CVEs
observed exploitation
nono source reports it
Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possible SSRF.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N