67% of public Apache Superset servers use a sample configuration access key

Researchers from Horizon3 identified security issues in most installations of the Apache Superset data analysis and visualization platform. On 2124 out of 3176 studied public Apache Superset servers, the use of the default encryption key specified in the sample configuration file was found. This key is used in the Flask Python library to generate session cookies, allowing an attacker who knows the key to create fake session parameters, connect to the Apache Superset web interface, and retrieve data from linked databases or execute code with Apache Superset's privileges.

Interestingly, researchers initially reported the issue to developers back in 2021. Following this, in the Apache Superset 1.4.1 release, created in January 2022, the value of the SECRET_KEY parameter was changed to the string "CHANGE_ME_TO_A_COMPLEX_RANDOM_SECRET", and a check was added in the code that logs a warning if that value is present.

In February of this year, researchers decided to re-scan vulnerable systems and found that few paid attention to the warning, and 67% of Apache Superset continued to use keys from configuration examples, deployment templates, or documentation. servers Some large companies, universities, and government agencies were among the organizations using default keys.

67% of public Apache Superset servers use a sample configuration access key

Specifying the working key in the configuration example is now regarded as a vulnerability (CVE-2023-27524), which was addressed in the Apache Superset 2.1 release by raising an error that blocks the platform from running when using the key specified in the example (only the key from the current version's configuration example is considered; old default keys and keys from templates and documentation are not blocked). A special script has been proposed to check for the vulnerability over the network.

67% of public Apache Superset servers use a sample configuration access key


Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster