← back
CVE-2023-42505mediumCWE-200

Apache Superset: Sensitive information disclosure on db connection details

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.3epss 1.0%
exploitation probability
1.0%top 38% of all CVEs
observed exploitation
nono source reports it
An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N