Skip to content

H3-2023-0001

Apache Superset Authentication Bypass Misconfiguration

Category SECURITY_MISCONFIGURATION
Base Score 8.1

Description

The Apache Superset server is configured with the default Flask secret key.

Impact

Attackers can use the well-known Flask secret key to forge authentication tokens and access the Superset application with administrative privileges. Attackers can access and modify data connected to the Superset server, harvest credentials, and potentially execute remote commands.

References