67% ืžื”ืฉืจืชื™ื ื”ืฆื™ื‘ื•ืจื™ื™ื ืฉืœ Apache Superset ืžืฉืชืžืฉื™ื ื‘ืžืคืชื— ื”ื’ื™ืฉื” ืžื“ื•ื’ืžื” ืœื”ื’ื“ืจื”

ื—ื•ืงืจื™ื ื‘-Horizon3 ืฉืžื• ืœื‘ ืœื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ื‘ืจื•ื‘ ื”ื”ืชืงื ื•ืช ืฉืœ ืคืœื˜ืคื•ืจืžืช ื”ื ื™ืชื•ื— ื•ื”ื”ื“ืžื™ื” ืฉืœ ื ืชื•ื ื™ื Apache Superset. ื‘-2124 ืžืชื•ืš 3176 ืฉืจืชื™ื ืฆื™ื‘ื•ืจื™ื™ื ืฉืœ Apache Superset ืฉื ื—ืงืจื•, ื–ื•ื”ื” ื”ืฉื™ืžื•ืฉ ื‘ืžืคืชื— ื”ื”ืฆืคื ื” ื”ื’ื ืจื™ ืฉืฆื•ื™ืŸ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” ืœื“ื•ื’ืžื”. ืžืคืชื— ื–ื” ืžืฉืžืฉ ื‘ืกืคืจื™ื™ืช ื”-Flask Python ืœื™ืฆื™ืจืช ืงื•ื‘ืฆื™ Cookie ืฉืœ ื”ืคืขืœื”, ืžื” ืฉืžืืคืฉืจ ืœืชื•ืงืฃ ืฉื™ื•ื“ืข ืืช ื”ืžืคืชื— ืœื™ืฆื•ืจ ืคืจืžื˜ืจื™ื ืคื™ืงื˜ื™ื‘ื™ื™ื ืฉืœ ื”ืคืขืœื”, ืœื”ืชื—ื‘ืจ ืœืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืœ Apache Superset ื•ืœื˜ืขื•ืŸ ื ืชื•ื ื™ื ืžื‘ืกื™ืกื™ ื ืชื•ื ื™ื ืงืฉื•ืจื™ื, ืื• ืœืืจื’ืŸ ื‘ื™ืฆื•ืข ืงื•ื“ ืขื ื–ื›ื•ื™ื•ืช Apache Superset .

ืžืขื ื™ื™ืŸ ืœืฆื™ื™ืŸ ืฉื”ื—ื•ืงืจื™ื ื“ื™ื•ื•ื—ื• ืœืจืืฉื•ื ื” ืขืœ ื”ื‘ืขื™ื” ืœืžืคืชื—ื™ื ื‘ืฉื ืช 2021, ื•ืœืื—ืจ ืžื›ืŸ, ื‘ืžื”ื“ื•ืจืช Apache Superset 1.4.1, ืฉื ื•ืฆืจื” ื‘ื™ื ื•ืืจ 2022, ื”ื•ื—ืœืฃ ื”ืขืจืš ืฉืœ ื”ืคืจืžื˜ืจ SECRET_KEY ื‘ืžื—ืจื•ื–ืช "CHANGE_ME_TO_A_COMPLEX_RANDOM_SECRET", ื‘ื“ื™ืงื” ื”ื™ื™ืชื” ื ื•ืกืฃ ืœืงื•ื“, ืื ื–ื” ืžืขืจื™ืš ื”ื•ืฆืืช ืื–ื”ืจื” ืœื™ื•ืžืŸ.

ื‘ืคื‘ืจื•ืืจ ื”ืฉื ื”, ื—ื•ืงืจื™ื ื”ื—ืœื™ื˜ื• ืœืกืจื•ืง ืžื—ื“ืฉ ืžืขืจื›ื•ืช ืคื’ื™ืขื•ืช ื•ื’ื™ืœื• ื›ื™ ืžืขื˜ ืื ืฉื™ื ืฉืžื™ื ืœื‘ ืœืื–ื”ืจื” ื•-67% ืžืฉืจืชื™ Apache Superset ืขื“ื™ื™ืŸ ืžืžืฉื™ื›ื™ื ืœื”ืฉืชืžืฉ ื‘ืžืคืชื—ื•ืช ืžื“ื•ื’ืžืื•ืช ืชืฆื•ืจื”, ืชื‘ื ื™ื•ืช ืคืจื™ืกื” ืื• ืชื™ืขื•ื“. ื‘ืžืงื‘ื™ืœ, ื›ืžื” ื—ื‘ืจื•ืช ื’ื“ื•ืœื•ืช, ืื•ื ื™ื‘ืจืกื™ื˜ืื•ืช ื•ืกื•ื›ื ื•ื™ื•ืช ืžืžืฉืœืชื™ื•ืช ื”ื™ื• ื‘ื™ืŸ ื”ืืจื’ื•ื ื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืžืคืชื—ื•ืช ื‘ืจื™ืจืช ืžื—ื“ืœ.

67% ืžื”ืฉืจืชื™ื ื”ืฆื™ื‘ื•ืจื™ื™ื ืฉืœ Apache Superset ืžืฉืชืžืฉื™ื ื‘ืžืคืชื— ื”ื’ื™ืฉื” ืžื“ื•ื’ืžื” ืœื”ื’ื“ืจื”

ืฆื™ื•ืŸ ืžืคืชื— ืขื‘ื•ื“ื” ื‘ืชืฆื•ืจื” ืœื“ื•ื’ืžื” ื ืชืคืกืช ื›ืขืช ื›ื—ื•ืœืฉื” (CVE-2023-27524), ื”ืžืชื•ืงื ืช ื‘ืžื”ื“ื•ืจื” ืฉืœ Apache Superset 2.1 ื‘ืืžืฆืขื•ืช ืคืœื˜ ืฉืœ ืฉื’ื™ืื” ื”ื—ื•ืกืžืช ืืช ื”ืฉืงืช ื”ืคืœื˜ืคื•ืจืžื” ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืžืคืชื— ืฉืฆื•ื™ืŸ ื‘ื“ื•ื’ืžื” (ืจืง ื”ืžืคืชื— ืฉืฆื•ื™ืŸ ื‘ื“ื•ื’ืžื” ืฉืœ ื”ืชืฆื•ืจื” ืฉืœ ื”ื’ืจืกื” ื”ื ื•ื›ื—ื™ืช ื ืœืงื— ื‘ื—ืฉื‘ื•ืŸ, ืžืคืชื—ื•ืช ืžืกื•ื’ ื™ืฉืŸ ื•ืžืคืชื—ื•ืช ืžืชื‘ื ื™ื•ืช ื•ืชื™ืขื•ื“ ืื™ื ื ื—ืกื•ืžื™ื). ื”ื•ืฆืข ืกืงืจื™ืคื˜ ืžื™ื•ื—ื“ ื›ื“ื™ ืœื‘ื“ื•ืง ืคื’ื™ืขื•ืช ื‘ืจืฉืช.

67% ืžื”ืฉืจืชื™ื ื”ืฆื™ื‘ื•ืจื™ื™ื ืฉืœ Apache Superset ืžืฉืชืžืฉื™ื ื‘ืžืคืชื— ื”ื’ื™ืฉื” ืžื“ื•ื’ืžื” ืœื”ื’ื“ืจื”


ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”