Apache

Superset

63 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Published 16.12.2019 22:15:11
  • Last modified 21.11.2024 04:22:47

In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab

  • EPSS 0.67%
  • Published 16.12.2019 22:15:11
  • Last modified 21.11.2024 04:22:47

In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query.

Exploit
  • EPSS 78.27%
  • Published 07.11.2018 14:29:00
  • Last modified 21.11.2024 04:13:06

Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.