VYPR

Superset

by Apache

pypi: superset

Source repositories

CVEs (70)

  • CVE-2023-43701MedNov 27, 2023
    risk 0.28cvss 4.3epss 0.01

    Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious actor to store malicious code into Chart's metadata, this code could get executed if a user specifically accesses a specific deprecated API endpoint. This issue…

  • CVE-2023-42501MedNov 27, 2023
    risk 0.28cvss 4.3epss 0.01

    Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations. This issue affects Apache Superset: before 2.1.2. Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma…

  • CVE-2023-32672MedSep 6, 2023
    risk 0.28cvss 4.3epss 0.01

    An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability can be exploited by leveraging a SQL…

  • CVE-2023-39264MedSep 6, 2023
    risk 0.28cvss 4.3epss 0.01

    By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoints to users. This vulnerability exists in Apache Superset versions up to and including 2.1.0.

  • CVE-2023-36388MedSep 6, 2023
    risk 0.28cvss 4.3epss 0.01

    Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possible SSRF.

  • CVE-2023-36387MedSep 6, 2023
    risk 0.28cvss 5.4epss 0.01

    An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.

  • CVE-2023-27526MedSep 6, 2023
    risk 0.28cvss 4.3epss 0.01

    A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up to and including 2.1.0. 

  • CVE-2024-39887MedJul 16, 2024
    risk 0.21cvss 4.3epss 0.04

    An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorization. To mitigate…

  • CVE-2021-37839MedJul 6, 2022
    risk 0.21cvss 4.3epss 0.01

    Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.

  • CVE-2023-27525LowApr 17, 2023
    risk 0.20cvss 3.1epss 0.01

    An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1

Page 4 of 4