Port 22

Apache Superset Vulnerability: Insecure Default Configuration Exposes Servers to RCE Attacks

The maintainers of theApache Supersetopen source data visualization software have released fixes to plug an insecure default configuration that could lead to remote code execution. The vulnerability, tracked asCVE-2023-27524(CVSS score: 8.9), impacts versions up to and including 2.0.1 and relates to the use of a default SECRET_KEY that could be abused by attackers to authenticate and access