CVE-2023-46104

Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.   This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*

History

13 Feb 2025, 18:15

Type Values Removed Values Added
Summary Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.   This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1. Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.   This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.
CWE CWE-400

14 Feb 2024, 14:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/02/14/2 -
  • () http://www.openwall.com/lists/oss-security/2024/02/14/3 -

29 Dec 2023, 17:05

Type Values Removed Values Added
CPE cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*
First Time Apache
Apache superset
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://lists.apache.org/thread/yxbxg4wryb7cb7wyybk11l5nqy0rsrvl - () https://lists.apache.org/thread/yxbxg4wryb7cb7wyybk11l5nqy0rsrvl - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2023/12/19/1 - () http://www.openwall.com/lists/oss-security/2023/12/19/1 - Mailing List

19 Dec 2023, 15:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2023/12/19/1 -

19 Dec 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-19 10:15

Updated : 2025-02-13 18:15


NVD link : CVE-2023-46104

Mitre link : CVE-2023-46104


JSON object : View

Products Affected

apache

  • superset
CWE

No CWE.