尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Apache Software Foundation | Apache Superset | 0 ~ 2.0.1 | - |
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Basic PoC for CVE-2023-27524: Insecure Default Configuration in Apache Superset | https://github.com/horizon3ai/CVE-2023-27524 | POC详情 |
| 2 | Apahce-Superset身份认证绕过漏洞(CVE-2023-27524)检测工具 | https://github.com/Okaytc/Superset_auth_bypass_check | POC详情 |
| 3 | Apache Superset Auth Bypass Vulnerability CVE-2023-27524. | https://github.com/antx-code/CVE-2023-27524 | POC详情 |
| 4 | A POC for the all new CVE-2023-27524 which allows for authentication bypass and gaining access to the admin dashboard. | https://github.com/MaanVader/CVE-2023-27524-POC | POC详情 |
| 5 | Perform With Apache-SuperSet Leaked Token [CSRF] | https://github.com/ThatNotEasy/CVE-2023-27524 | POC详情 |
| 6 | None | https://github.com/TardC/CVE-2023-27524 | POC详情 |
| 7 | CVE-2023-27524 | https://github.com/necroteddy/CVE-2023-27524 | POC详情 |
| 8 | None | https://github.com/jakabakos/CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE | POC详情 |
| 9 | Apache Superset 默认SECRET_KEY 漏洞(CVE-2023-27524) | https://github.com/CN016/Apache-Superset-SECRET_KEY-CVE-2023-27524- | POC详情 |
| 10 | CVE-2023-27524 | https://github.com/NguyenCongHaiNam/Research-CVE-2023-27524 | POC详情 |
| 11 | Tool for finding CVE-2023-27524 (Apache Superset - Authentication Bypass) | https://github.com/karthi-the-hacker/CVE-2023-27524 | POC详情 |
| 12 | Tool for finding CVE-2023-27524 (Apache Superset - Authentication Bypass) | https://github.com/Cappricio-Securities/CVE-2023-27524 | POC详情 |
| 13 | Apache Superset Auth Bypass Vulnerability CVE-2023-27524. | https://github.com/ZZ-SOCMAP/CVE-2023-27524 | POC详情 |
| 14 | CVE-2023-27524 | https://github.com/h1n4mx0/Research-CVE-2023-27524 | POC详情 |
| 15 | Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-27524.yaml | POC详情 |
| 16 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Apache%20Superset%20%E7%A1%AC%E7%BC%96%E7%A0%81%20JWT%20%E5%AF%86%E9%92%A5%E5%AF%BC%E8%87%B4%E8%AE%A4%E8%AF%81%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E%20CVE-2023-27524.md | POC详情 |
| 17 | https://github.com/vulhub/vulhub/blob/master/superset/CVE-2023-27524/README.md | POC详情 | |
| 18 | Apache Superset Auth Bypass (CVE-2023-27524) | https://github.com/tardc/CVE-2023-27524 | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论