Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-1932

An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.2%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2020-1932
  • Apache » Superset » Version: 0.34.0
    cpe:2.3:a:apache:superset:0.34.0
  • Apache » Superset » Version: 0.34.1
    cpe:2.3:a:apache:superset:0.34.1
  • Apache » Superset » Version: 0.35.0
    cpe:2.3:a:apache:superset:0.35.0
  • Apache » Superset » Version: 0.35.1
    cpe:2.3:a:apache:superset:0.35.1


Contact Us

Shodan ® - All rights reserved