Apache Superset 2.0.1 with the default SECRET_KEY, vulnerable to CVE-2023-27524: anyone who knows the key signs a Flask session cookie for user 1 and is logged in as admin.
Pas commencéDockercommit a7678adx86_64 · aarch64Secret
Exploit CVE-2023-27524 to forge an admin session in Superset and read the flag from the admin's dashboard (its title).
Le brief de ce lab se trouve dans son dépôt.