Apache

Superset

63 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 51.48%
  • Published 16.07.2024 10:15:03
  • Last modified 13.02.2025 18:18:09

An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL ...

  • EPSS 6.55%
  • Published 20.06.2024 09:15:11
  • Last modified 13.02.2025 18:18:05

Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are se...

  • EPSS 0.06%
  • Published 07.05.2024 14:15:10
  • Last modified 11.02.2025 16:33:10

An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or...

  • EPSS 0.11%
  • Published 28.02.2024 12:15:47
  • Last modified 13.02.2025 18:17:08

Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1...

  • EPSS 0.56%
  • Published 28.02.2024 12:15:47
  • Last modified 12.02.2025 10:15:12

A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are reco...

  • EPSS 0.13%
  • Published 28.02.2024 12:15:47
  • Last modified 13.02.2025 18:17:09

Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get acc...

  • EPSS 0.19%
  • Published 28.02.2024 12:15:47
  • Last modified 13.02.2025 18:17:17

A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object. However, it's important to note that access to the analytical data o...

  • EPSS 0.1%
  • Published 28.02.2024 10:15:09
  • Last modified 31.12.2024 16:16:15

An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an error on the database. This error is not properly handled by Apache Superset and may inadvert...

  • EPSS 1.03%
  • Published 14.02.2024 12:15:47
  • Last modified 13.02.2025 18:17:06

This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datase...

  • EPSS 0.3%
  • Published 23.01.2024 15:15:11
  • Last modified 21.11.2024 08:33:40

A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on charts or dashboards could store a script or add a specific HTML snippet that would act as a stored ...