Autore: Angelo Barbosa

CVE-2023-6287 | Tribe29 Checkmk Appliance up to 1.6.7 Log File get request method with sensitive query strings

A vulnerability, which was classified as problematic, was found in Tribe29 Checkmk Appliance up to 1.6.7. Affected is an unknown function of the component Log File Handler. The manipulation leads to use of get request method with sensitive query strings. This vulnerability is traded as CVE-2023-6287. Local access is required to approach this attack. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-40610 | Apache Superset up to 2.1.2 CTE authorization

A vulnerability was found in Apache Superset up to 2.1.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component CTE Handler. The manipulation leads to incorrect authorization. This vulnerability is known as CVE-2023-40610. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-42501 | Apache Superset up to 2.1.1 Gamma Role default permission

A vulnerability was found in Apache Superset up to 2.1.1. It has been classified as critical. Affected is an unknown function of the component Gamma Role Handler. The manipulation leads to incorrect default permissions. This vulnerability is traded as CVE-2023-42501. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più