Security Advisory

CVE-2020-1932

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-01-28 00:38:15
Last updated 2024-08-04 06:54:00
Assigner apache
CVSS score not scored
State PUBLISHED

Description

An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset.