CVE-2023-27524 is an authentication bypass/session forgery issue in Apache Superset affecting versions up to and including 2.0.1, and more generally versions prior to 2.1 when deployed with an unchanged default or hard-coded SECRET_KEY. Superset uses SECRET_KEY to sign session cookies and protect sensitive application data. If an installation retains a known default SECRET_KEY instead of replacing it with a unique random value as required by the installation guidance, a remote attacker who knows the default key can forge valid session material and authenticate as another user, including an administrator. Supporting reporting indicates that prior versions contained hard-coded/default secret keys and that exploitation can result in administrator web access.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This repository contains a single Metasploit module (modules/exploits/linux/http/apache_superset_cookie_sig_rce.rb) that exploits multiple vulnerabilities in Apache Superset (<= 2.0.0) related to insecure default Flask secret keys and improper session handling. The exploit forges a signed session cookie to impersonate an administrator, accesses the Superset database to extract credentials, and injects a malicious pickled Python payload to achieve remote code execution (RCE) on the server. The module supports cleanup by removing any artifacts (dashboard, SQL Lab tab, database mapping) created during exploitation. The exploit is weaponized, supporting customizable Python payloads via Metasploit, and targets network-accessible Superset instances. The code is written in Ruby and leverages Metasploit's HTTP client and payload framework. Key endpoints include the login page and various Superset API endpoints for dashboard and database management.
This repository contains a single Metasploit auxiliary module targeting Apache Superset (<= 2.0.0, >= 1.4.1) installations that use a default or known Flask secret key (CVE-2023-27524). The module exploits the ability to forge Flask session cookies, allowing privilege escalation from a regular user to an administrator. The attacker must have valid user credentials and knowledge of the admin user ID. The module attempts to discover the secret key, forges a session cookie with admin privileges, and uses it to access the Superset API to enumerate and extract database credentials. The main endpoints targeted are '/login' for authentication, '/api/v1/me/' for session validation, and '/api/v1/database/<id>' for credential extraction. The exploit is operational and provides real credential extraction, but does not provide a customizable payload beyond the forged session cookie.
This repository contains a functional exploit for CVE-2023-27524, targeting Apache Superset instances (up to v2.0.1) that use default or weak Flask SECRET_KEY values. The exploit (exploit.py) is a Python script that automates the process of identifying vulnerable Superset instances, brute-forcing the SECRET_KEY using a provided wordlist (10k_most_common_passwords.txt), forging admin session cookies, and escalating access to perform post-authentication actions. These actions include enumerating databases and users, extracting credentials, executing arbitrary OS commands, and establishing a reverse shell on either the Superset or database server. The script is command-line driven, with options for validation, enumeration, command execution, and reverse shell setup. The README.md provides detailed usage instructions, examples, and context about the vulnerability. The requirements.txt lists necessary Python dependencies. The exploit is operational and can be used for both vulnerability validation and post-exploitation activities, provided the target is misconfigured as described.
This repository provides a Python proof-of-concept exploit for CVE-2023-27524, targeting Apache Superset instances that use default or weak Flask SECRET_KEY values. The main script, CVE-2023-27524.py, attempts to retrieve a session cookie from the /login/ endpoint, decode it, and verify if it is signed with any known default keys. If successful, it forges a new session cookie for a specified user (default: user_id=1), effectively bypassing authentication. With the --validate flag, the script uses the forged cookie to access the Superset API and enumerate available databases, demonstrating the impact of the vulnerability. The repository includes a README with usage instructions, example output, and mitigation advice, as well as a requirements.txt specifying dependencies (flask-unsign, requests). No hardcoded IPs or domains are present; the script is designed to be run against a user-supplied Superset URL. The exploit is a POC and does not provide a weaponized or post-exploitation payload, but demonstrates a critical authentication bypass and data enumeration capability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A session forgery vulnerability in Apache Superset that could allow attackers to impersonate users or hijack sessions.
An authentication bypass / insecure default configuration issue in Apache Superset where hard-coded/default SECRET_KEY values can allow remote attackers to authenticate as an administrator, enabling follow-on actions including remote code execution and credential harvesting.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.