CVE-2023-25504 MEDIUM

CVE-2023-25504: Apache Superset: Possible SSRF on import datasets

Vendor Apache Software Foundation
Product Apache Superset
Weakness CWE-918 · SSRF
Published April 17, 2023
Last update February 13, 2025

CVSS base score

4.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

Description

A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery attacks and query internal resources on behalf of the server where Superset is deployed. This vulnerability exists in Apache Superset versions up to and including 2.0.1.

Key dates

Disclosure timeline

April 17, 2023 CVE published
February 13, 2025 Record updated