Apache

Superset

68 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.92%
  • Veröffentlicht 27.04.2021 10:15:09
  • Zuletzt bearbeitet 21.11.2024 05:59:07

Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a ...

  • EPSS 4.3%
  • Veröffentlicht 05.03.2021 12:15:12
  • Zuletzt bearbeitet 21.11.2024 05:58:45

Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user could inject javascript code executing unwanted actio...

  • EPSS 0.12%
  • Veröffentlicht 30.09.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:02:13

In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines could access information via a number of templated fields including the contents of query description...

  • EPSS 0.73%
  • Veröffentlicht 17.09.2020 13:15:15
  • Zuletzt bearbeitet 21.11.2024 05:02:12

While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text fields in the product that would allow arbitrary access to Python’s `os` package in the web applicat...

  • EPSS 0.23%
  • Veröffentlicht 28.01.2020 01:15:12
  • Zuletzt bearbeitet 21.11.2024 05:11:38

An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented AP...

  • EPSS 0.67%
  • Veröffentlicht 16.12.2019 22:15:11
  • Zuletzt bearbeitet 21.11.2024 04:22:47

In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query.

  • EPSS 0.14%
  • Veröffentlicht 16.12.2019 22:15:11
  • Zuletzt bearbeitet 21.11.2024 04:22:47

In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab

Exploit
  • EPSS 69.85%
  • Veröffentlicht 07.11.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:13:06

Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.