Apache

Superset

68 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 13.05.2025 08:21:21
  • Zuletzt bearbeitet 29.09.2025 21:49:41

Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade t...

  • EPSS 1.04%
  • Veröffentlicht 12.12.2024 15:15:17
  • Zuletzt bearbeitet 12.02.2025 10:15:14

Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query, enabling its execution. Non p...

  • EPSS 0.34%
  • Veröffentlicht 09.12.2024 14:15:12
  • Zuletzt bearbeitet 12.02.2025 10:15:13

Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API.  issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are recommended to ...

  • EPSS 0.13%
  • Veröffentlicht 09.12.2024 14:15:12
  • Zuletzt bearbeitet 11.02.2025 16:27:31

Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.

  • EPSS 0.22%
  • Veröffentlicht 09.12.2024 14:15:12
  • Zuletzt bearbeitet 15.07.2025 16:29:47

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorizati...

  • EPSS 61.25%
  • Veröffentlicht 16.07.2024 10:15:03
  • Zuletzt bearbeitet 13.02.2025 18:18:09

An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL ...

  • EPSS 12.37%
  • Veröffentlicht 20.06.2024 09:15:11
  • Zuletzt bearbeitet 13.02.2025 18:18:05

Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are se...

  • EPSS 0.08%
  • Veröffentlicht 07.05.2024 14:15:10
  • Zuletzt bearbeitet 11.02.2025 16:33:10

An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or...

  • EPSS 0.18%
  • Veröffentlicht 28.02.2024 12:15:47
  • Zuletzt bearbeitet 13.02.2025 18:17:17

A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object. However, it's important to note that access to the analytical data o...

  • EPSS 0.17%
  • Veröffentlicht 28.02.2024 12:15:47
  • Zuletzt bearbeitet 13.02.2025 18:17:09

Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get acc...