Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wr6g-9wcr-cmqj

Опубликовано: 28 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5

Описание

Apache Superset: Improper data authorization when creating a new dataset

Apache Superset with custom roles that include can write on dataset and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to unauthorized data. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.

Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.

Пакеты

Наименование

apache-superset

pip
Затронутые версииВерсия исправления

<= 3.0.3

3.0.4

Наименование

apache-superset

pip
Затронутые версииВерсия исправления

>= 3.1.0, < 3.1.1

3.1.1

EPSS

Процентиль: 39%
0.00174
Низкий

5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5
nvd
почти 2 года назад

Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to unauthorized data. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.

EPSS

Процентиль: 39%
0.00174
Низкий

5 Medium

CVSS3

Дефекты

CWE-863