ID:11012 - Exploit for Insecure default initialization of resource in Apache Superset - CVE-2023-27524
Published: December 19, 2024
Apache Superset
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to the application does not alter the default configured SECRET_KEY by itself. A remote attacker can authenticate and access unauthorized resources if the software installation was not performed according to vendor's instructions.