module

Apache Superset Signed Cookie Priv Esc

Disclosed
Apr 25, 2023
Created
Sep 13, 2023

Description

Apache Superset versions These cookies can therefore be forged. If a user is able to login to the site, they can decode the cookie, set their user_id to that
of an administrator, and re-sign the cookie. This valid cookie can then be used to login as the targeted user and retrieve database
credentials saved in Apache Superset.

Authors

h00die
paradoxis
Spencer McIntyre
Naveen Sunkavally

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/gather/apache_superset_cookie_sig_priv_esc
msf auxiliary(apache_superset_cookie_sig_priv_esc) > show actions
...actions...
msf auxiliary(apache_superset_cookie_sig_priv_esc) > set ACTION < action-name >
msf auxiliary(apache_superset_cookie_sig_priv_esc) > show options
...show and set options...
msf auxiliary(apache_superset_cookie_sig_priv_esc) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.