4.1.2
5 years ago
27 days ago
Known vulnerabilities in the apache-superset package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Improper Authorization through the SQLLab component. An attacker can execute unauthorized write operations by crafting a specially designed SQL DML statement that is incorrectly identified as a read-only query. Note: This is only exploitable if the database connection is not set with a readonly user. How to fix Improper Authorization? Upgrade | [,4.1.0rc2) |
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to SQL Injection due to improper handling of certain PostgreSQL functions in the SQL parsing and authorization process. An attacker can execute unauthorized SQL commands by exploiting these engine-specific functions that are not adequately checked. Note:
This issue is a follow-up to CVE-2024-39887 with additional disallowed PostgreSQL functions now included: How to fix SQL Injection? Upgrade | [,4.1.0rc2) |
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Improper Authorization due to the enabled How to fix Improper Authorization? Upgrade | [2.0.0,4.1.0rc3) |
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to SQL Injection by using engine-specific functions that are not adequately checked. This is only exploitable if the How to fix SQL Injection? Upgrade | [,4.0.2) |
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Arbitrary File Read by allowing an authenticated attacker to create a MariaDB connection with Note: This is only exploitable if both the MariaDB server and the local mysql client on the web server are set to allow for local infile. How to fix Arbitrary File Read? Upgrade | [,3.1.3)[4.0.0,4.0.1) |
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Incorrect Authorization due to the improper handling of REST API requests. An authenticated attacker can access unauthorized metadata that they are not authorized to view by submitting a targeted request. How to fix Incorrect Authorization? Upgrade | [,3.1.2)[4.0.0rc1,4.0.0rc2) |
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Improper Authorization on dashboards and charts import. A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object. Note: The access to the analytical data of these charts and dashboards would still be subject to validation based on data access privileges. How to fix Improper Authorization? Upgrade | [,3.0.4)[3.1.0,3.1.1) |
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File. A user with Alerts & Reports privileges to create Alerts can cause a malicious SQL statement to throw and error and have its contents logged. Thee error is not properly handled and can expose sensitive data. How to fix Insertion of Sensitive Information into Log File? Upgrade | [,3.0.4)[3.1.0rc1,3.1.1) |
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Improper Authorization when creating a new virtual dataset using custom roles that include "can write on dataset". This allows users to access data in other datasets to which they do not otherwise have access. How to fix Improper Authorization? Upgrade | [,3.0.4)[3.1.0rc1,3.1.1) |
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Incorrect Authorization when processing nested SQL statements in SQLLab, allowing a user to access unauthorized data. How to fix Incorrect Authorization? Upgrade | [,3.0.4)[3.1.0rc1,3.1.1) |
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to SQL Injection in an embedded context, allowing a guest user to expose information from the analytics database via chart data REST API call. How to fix SQL Injection? Upgrade | [,3.0.4)[3.1.0rc1,3.1.1) |
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the "Dashboard Title" and "Chart Title" due to improper user input sanitization. An authenticated attacker with create/update permissions could inject a malicious script or HTML snippet, leading to the execution of arbitrary code in the context of the user's browser session. Note For 2.X versions, users should change their config to include:
How to fix Cross-site Scripting (XSS)? Upgrade | [,3.0.3) |
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling. An authenticated attacker can initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to denial of service. How to fix Allocation of Resources Without Limits or Throttling? Upgrade | [,2.1.3)[3.0.0rc1,3.0.0) |
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Open Redirect when the dataset link updating process is manipulated. An attacker can change a dataset link to an untrusted site by spoofing the HTTP Host header. This is only exploitable if the attacker is authenticated and has update datasets permission. How to fix Open Redirect? Upgrade | [,3.0.0) |
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Information Exposure. An authenticated attacker with read permissions on database connections metadata can access sensitive information such as the connection's username by exploiting this vulnerability. How to fix Information Exposure? Upgrade | [,3.0.0) |