• Online, Self-Paced
Course Description

CVE-2023-27524 is a critical vulnerability in Apache Superset, affecting versions up to 2.0.1. It enables attackers to bypass authentication by exploiting weak or default SECRET_KEY values. Attackers can forge session cookies to gain admin access, leading to potential remote code execution and unauthorized data access.

Learning Objectives

By the end of this course, you should be able to:
- Define the vulnerability, describe its root cause, and communicate its significance to key organizational stakeholders.
- Exploit this vulnerability using publicly available exploit code.
- Execute various mitigation tactics to reduce risk.

Framework Connections

The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):

Competency Areas