USD 110M Loan Portfolio at Risk Due to Vendor’s Apache Superset Insecure Default Initialization of Resource Vulnerability [CVE-2023-27524]
ID: c6d1b359-ac12-5aa8-a1b7-80034cfb2ddf
STIX ID: report--c6d1b359-ac12-5aa8-a1b7-80034cfb2ddf
Feed Name: CloudSEK Blog
Threat Score
CloudSEK’s SVigil discovered an unauthenticated Apache Superset dashboard owned by a vendor of a major bank that openly exposed over 2.6 million accounts, USD 110M in outstanding loans, PII, borrower communication logs, and internal co-lending dashboards due to default SECRET_KEY and missing authentication controls; the report details business and regulatory impact and recommends upgrading Superset, enforcing authentication, restricting access, and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
