CVE-2023-46104

Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.   This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*

History

13 Feb 2025, 18:15

Type Values Removed Values Added
Summary (en) Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.   This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1. (en) Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.   This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.

21 Nov 2024, 08:27

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2023/12/19/1 - Mailing List () http://www.openwall.com/lists/oss-security/2023/12/19/1 - Mailing List
References () http://www.openwall.com/lists/oss-security/2024/02/14/2 - () http://www.openwall.com/lists/oss-security/2024/02/14/2 -
References () http://www.openwall.com/lists/oss-security/2024/02/14/3 - () http://www.openwall.com/lists/oss-security/2024/02/14/3 -
References () https://lists.apache.org/thread/yxbxg4wryb7cb7wyybk11l5nqy0rsrvl - Vendor Advisory () https://lists.apache.org/thread/yxbxg4wryb7cb7wyybk11l5nqy0rsrvl - Vendor Advisory

14 Feb 2024, 14:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/02/14/2 -
  • () http://www.openwall.com/lists/oss-security/2024/02/14/3 -

29 Dec 2023, 17:05

Type Values Removed Values Added
Summary
  • (es) El consumo incontrolado de recursos puede ser provocado por un atacante autenticado que carga un ZIP malicioso para importar bases de datos, paneles o conjuntos de datos. Esta vulnerabilidad existe en las versiones de Apache Superset hasta la 2.1.2 inclusive y en las versiones 3.0.0, 3.0.1.
References () http://www.openwall.com/lists/oss-security/2023/12/19/1 - () http://www.openwall.com/lists/oss-security/2023/12/19/1 - Mailing List
References () https://lists.apache.org/thread/yxbxg4wryb7cb7wyybk11l5nqy0rsrvl - () https://lists.apache.org/thread/yxbxg4wryb7cb7wyybk11l5nqy0rsrvl - Vendor Advisory
First Time Apache
Apache superset
CPE cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*

19 Dec 2023, 15:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2023/12/19/1 -

19 Dec 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-19 10:15

Updated : 2025-02-13 18:15


NVD link : CVE-2023-46104

Mitre link : CVE-2023-46104

CVE.ORG link : CVE-2023-46104


JSON object : View

Products Affected

apache

  • superset
CWE
CWE-400

Uncontrolled Resource Consumption