Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-392c-vjfv-h7wr

Опубликовано: 27 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.3

Описание

Duplicate Advisory: Apache Superset - Elevation of Privilege

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-f678-j579-4xf5. This link is maintained to preserve external references.

Original Description

Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database connection that allows access to both the examples schema and Apache Superset's metadata database, an attacker using a specially crafted CTE SQL statement could change data on the metadata database. This weakness could result on tampering with the authentication/authorization data.

Пакеты

Наименование

apache-superset

pip
Затронутые версииВерсия исправления

< 2.1.2

2.1.2

6.3 Medium

CVSS3

Дефекты

CWE-863

6.3 Medium

CVSS3

Дефекты

CWE-863