Medium severity4.3NVD Advisory· Published Nov 28, 2023· Updated Jun 17, 2026
CVE-2023-42505
CVE-2023-42505
Description
An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username.
This issue affects Apache Superset before 3.0.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-supersetPyPI | < 3.0.0 | 3.0.0 |
Affected products
4- osv-coords2 versions
< 3.0.0+ 1 more
- (no CPE)range: < 3.0.0
- (no CPE)range: < 3.0.0
Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2023/11/28/5nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-fgpw-4w69-j256ghsaADVISORY
- lists.apache.org/thread/bd0fhtfzrtgo1q8x35tpm8ms144d1t2ynvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-42505ghsaADVISORY
News mentions
0No linked articles in our index yet.