Executive brief
Apache Superset versions up to 2.0.1 use an insecure default SECRET_KEY for session signing. Attackers can use this known default key to forge session cookies, allowing them to authenticate and access unauthorized resources on installations that have not changed the default configuration.
Affected products
- Apache Superset up to and including 2.0.1
Timeline
- 2023-04-24: disclosed: Initial disclosure on oss-security mailing list
- 2024-01-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-01-08: other: Published to NVD