Description
Apache Superset versions <= 2.0.0 utilize Flask with a known default secret key which is used to sign HTTP cookies. These cookies can therefore be forged. If a user is able to login to the site, they can decode the cookie, set their user_id to that of an administrator, and re-sign the cookie. This valid cookie can then be used to login as the targeted user and retrieve database credentials saved in Apache Superset.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/gather/apache/superset_cookie_sig_priv_escmsf undefined(superset_cookie_sig_priv_esc) > show actions ...actions...msf undefined(superset_cookie_sig_priv_esc) > set ACTION < action-name >msf undefined(superset_cookie_sig_priv_esc) > show options ...show and set options...msf undefined(superset_cookie_sig_priv_esc) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub