Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhpq-m962-mg92

Опубликовано: 14 авг. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access

Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterating through the datasource_id in the URL, an attacker can enumerate and confirm the existence and names of protected datasources, leading to sensitive information disclosure.

This issue affects Apache Superset: before 5.0.0.

Users are recommended to upgrade to version 5.0.0, which fixes the issue.

Пакеты

Наименование

apache-superset

pip
Затронутые версииВерсия исправления

< 5.0.0

5.0.0

EPSS

Процентиль: 16%
0.00052
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 6.5
nvd
6 месяцев назад

Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterating through the datasource_id in the URL, an attacker can enumerate and confirm the existence and names of protected datasources, leading to sensitive information disclosure. This issue affects Apache Superset: before 5.0.0. Users are recommended to upgrade to version 5.0.0, which fixes the issue.

CVSS3: 6.5
fstec
6 месяцев назад

Уязвимость программного обеспечения визуализации данных Apache Superset, связанная с неправильным контролем доступа в конечной точке /explore, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 16%
0.00052
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-285