Apache

Superset

68 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 24.02.2026 13:02:55
  • Zuletzt bearbeitet 26.02.2026 16:27:28

Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included restrictions for engines like PostgreSQL, a vulnerab...

  • EPSS 0.03%
  • Veröffentlicht 24.02.2026 12:54:09
  • Zuletzt bearbeitet 25.02.2026 14:36:33

Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This i...

  • EPSS 0.04%
  • Veröffentlicht 24.02.2026 12:52:44
  • Zuletzt bearbeitet 25.02.2026 14:38:02

An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces permission checks to prevent users from querying unauthorized data. However...

  • EPSS 0.06%
  • Veröffentlicht 24.02.2026 12:52:11
  • Zuletzt bearbeitet 25.02.2026 14:37:49

A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve a list of objects associated with a specific tag. W...

  • EPSS 0.04%
  • Veröffentlicht 24.02.2026 12:51:07
  • Zuletzt bearbeitet 26.02.2026 16:25:58

An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a PostgreSQL database connection. While the system effectively blocks stan...

  • EPSS 0.07%
  • Veröffentlicht 14.08.2025 13:18:53
  • Zuletzt bearbeitet 04.11.2025 22:16:31

Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterating through ...

  • EPSS 0.08%
  • Veröffentlicht 14.08.2025 13:18:10
  • Zuletzt bearbeitet 04.11.2025 22:16:30

A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute f...

  • EPSS 0.05%
  • Veröffentlicht 14.08.2025 13:17:33
  • Zuletzt bearbeitet 04.11.2025 22:16:30

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and g...

  • EPSS 0.2%
  • Veröffentlicht 14.08.2025 13:16:27
  • Zuletzt bearbeitet 04.11.2025 22:16:30

When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as tab...

  • EPSS 0.17%
  • Veröffentlicht 30.05.2025 08:26:15
  • Zuletzt bearbeitet 04.06.2025 18:29:44

An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unau...