Apache

Superset

63 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 51.48%
  • Veröffentlicht 16.07.2024 10:15:03
  • Zuletzt bearbeitet 13.02.2025 18:18:09

An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL ...

  • EPSS 6.55%
  • Veröffentlicht 20.06.2024 09:15:11
  • Zuletzt bearbeitet 13.02.2025 18:18:05

Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are se...

  • EPSS 0.06%
  • Veröffentlicht 07.05.2024 14:15:10
  • Zuletzt bearbeitet 11.02.2025 16:33:10

An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or...

  • EPSS 0.11%
  • Veröffentlicht 28.02.2024 12:15:47
  • Zuletzt bearbeitet 13.02.2025 18:17:08

Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1...

  • EPSS 0.56%
  • Veröffentlicht 28.02.2024 12:15:47
  • Zuletzt bearbeitet 12.02.2025 10:15:12

A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are reco...

  • EPSS 0.13%
  • Veröffentlicht 28.02.2024 12:15:47
  • Zuletzt bearbeitet 13.02.2025 18:17:09

Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get acc...

  • EPSS 0.19%
  • Veröffentlicht 28.02.2024 12:15:47
  • Zuletzt bearbeitet 13.02.2025 18:17:17

A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object. However, it's important to note that access to the analytical data o...

  • EPSS 0.1%
  • Veröffentlicht 28.02.2024 10:15:09
  • Zuletzt bearbeitet 31.12.2024 16:16:15

An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an error on the database. This error is not properly handled by Apache Superset and may inadvert...

  • EPSS 1.03%
  • Veröffentlicht 14.02.2024 12:15:47
  • Zuletzt bearbeitet 13.02.2025 18:17:06

This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datase...

  • EPSS 0.3%
  • Veröffentlicht 23.01.2024 15:15:11
  • Zuletzt bearbeitet 21.11.2024 08:33:40

A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on charts or dashboards could store a script or add a specific HTML snippet that would act as a stored ...