
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
CVE-2024-23952 is a duplicate of CVE-2023-46104, created to correct version ranges for affected Apache Superset installations. The vulnerability affects Apache Superset versions before 2.1.3 and versions 3.0.0 before 3.0.2. The issue was discovered by Dor Konis from GE Vernova (OSS Security).
The vulnerability is classified as Uncontrolled Resource Consumption (CWE-400). It has a CVSS v3.1 base score of 6.5 (Medium), with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The issue can be triggered by an authenticated attacker who uploads a malicious ZIP file when importing databases, dashboards, or datasets (NVD).
When exploited, this vulnerability can lead to uncontrolled resource consumption in the Apache Superset system, potentially affecting system availability. The attack requires authentication but can be executed without user interaction (NVD).
Users should upgrade to Apache Superset version 2.1.3 or later for the 2.x series, or version 3.0.2 or later for the 3.x series to address this vulnerability (OSS Security).
Security researchers have noted that this CVE was potentially misused as it is a duplicate of CVE-2023-46104, with the only change being a correction in the affected version ranges from 'before 3.0.1' to 'before 3.0.2' (OSS Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”