Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-299q-3p96-5898

Опубликовано: 07 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Apache Superset Incorrect Authorization vulnerability

An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request. This issue affects Apache Superset before 3.1.2.

Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue.

Пакеты

Наименование

apache-superset

pip
Затронутые версииВерсия исправления

< 3.1.2

3.1.2

EPSS

Процентиль: 14%
0.00045
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue.

EPSS

Процентиль: 14%
0.00045
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863