CVE-2021-44451
- EPSS 71.27%
- Published 01.02.2022 14:15:09
- Last modified 21.11.2024 06:31:00
Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher.
CVE-2021-42250
- EPSS 1%
- Published 17.11.2021 15:15:08
- Last modified 21.11.2024 06:27:27
Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs.
CVE-2021-41972
- EPSS 0.31%
- Published 12.11.2021 19:15:08
- Last modified 21.11.2024 06:27:00
Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way.
CVE-2021-41971
- EPSS 1.3%
- Published 18.10.2021 15:15:07
- Last modified 21.11.2024 06:27:00
Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malicious authenticated user sends an http request with a custom URL.
CVE-2021-32609
- EPSS 14.04%
- Published 18.10.2021 15:15:07
- Last modified 21.11.2024 06:07:22
Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page.
CVE-2021-28125
- EPSS 8.85%
- Published 27.04.2021 10:15:09
- Last modified 21.11.2024 05:59:07
Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a ...
CVE-2021-27907
- EPSS 2.2%
- Published 05.03.2021 12:15:12
- Last modified 21.11.2024 05:58:45
Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user could inject javascript code executing unwanted actio...
CVE-2020-13952
- EPSS 0.12%
- Published 30.09.2020 21:15:12
- Last modified 21.11.2024 05:02:13
In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines could access information via a number of templated fields including the contents of query description...
CVE-2020-13948
- EPSS 0.73%
- Published 17.09.2020 13:15:15
- Last modified 21.11.2024 05:02:12
While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text fields in the product that would allow arbitrary access to Python’s `os` package in the web applicat...
CVE-2020-1932
- EPSS 0.23%
- Published 28.01.2020 01:15:12
- Last modified 21.11.2024 05:11:38
An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented AP...