CVE-2025-55673
- EPSS 0.56%
- Veröffentlicht 14.08.2025 13:16:27
- Zuletzt bearbeitet 04.11.2025 22:16:30
When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as tab...
CVE-2025-48912
- EPSS 0.69%
- Veröffentlicht 30.05.2025 08:26:15
- Zuletzt bearbeitet 04.06.2025 18:29:44
An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unau...
CVE-2025-27696
- EPSS 1.21%
- Veröffentlicht 13.05.2025 08:21:21
- Zuletzt bearbeitet 29.09.2025 21:49:41
Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade t...
CVE-2024-55633
- EPSS 2.56%
- Veröffentlicht 12.12.2024 15:15:17
- Zuletzt bearbeitet 12.02.2025 10:15:14
Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query, enabling its execution. Non p...
CVE-2024-53947
- EPSS 0.81%
- Veröffentlicht 09.12.2024 14:15:12
- Zuletzt bearbeitet 15.07.2025 16:29:47
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorizati...
CVE-2024-53948
- EPSS 0.79%
- Veröffentlicht 09.12.2024 14:15:12
- Zuletzt bearbeitet 11.02.2025 16:27:31
Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.
CVE-2024-53949
- EPSS 0.65%
- Veröffentlicht 09.12.2024 14:15:12
- Zuletzt bearbeitet 12.02.2025 10:15:13
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API. issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are recommended to ...
CVE-2024-39887
- EPSS 4.43%
- Veröffentlicht 16.07.2024 10:15:03
- Zuletzt bearbeitet 13.02.2025 18:18:09
An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL ...
CVE-2024-34693
- EPSS 1.57%
- Veröffentlicht 20.06.2024 09:15:11
- Zuletzt bearbeitet 13.02.2025 18:18:05
Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are se...
CVE-2024-28148
- EPSS 0.7%
- Veröffentlicht 07.05.2024 14:15:10
- Zuletzt bearbeitet 11.02.2025 16:33:10
An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or...