Apache

Superset

70 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.77%
  • Veröffentlicht 18.10.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:00

Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malicious authenticated user sends an http request with a custom URL.

  • EPSS 1.66%
  • Veröffentlicht 18.10.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:22

Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page.

  • EPSS 63.77%
  • Veröffentlicht 27.04.2021 10:15:09
  • Zuletzt bearbeitet 21.11.2024 05:59:07

Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a ...

  • EPSS 86.39%
  • Veröffentlicht 05.03.2021 12:15:12
  • Zuletzt bearbeitet 21.11.2024 05:58:45

Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user could inject javascript code executing unwanted actio...

  • EPSS 2.02%
  • Veröffentlicht 30.09.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:02:13

In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines could access information via a number of templated fields including the contents of query description...

  • EPSS 3.1%
  • Veröffentlicht 17.09.2020 13:15:15
  • Zuletzt bearbeitet 21.11.2024 05:02:12

While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text fields in the product that would allow arbitrary access to Python’s `os` package in the web applicat...

  • EPSS 1.35%
  • Veröffentlicht 28.01.2020 01:15:12
  • Zuletzt bearbeitet 21.11.2024 05:11:38

An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented AP...

  • EPSS 2.79%
  • Veröffentlicht 16.12.2019 22:15:11
  • Zuletzt bearbeitet 21.11.2024 04:22:47

In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab

  • EPSS 2.8%
  • Veröffentlicht 16.12.2019 22:15:11
  • Zuletzt bearbeitet 21.11.2024 04:22:47

In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query.

Exploit
  • EPSS 52.76%
  • Veröffentlicht 07.11.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:13:06

Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.