Логотип exploitDog
bind:CVE-2024-27315
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-27315

Количество 2

Количество 2

nvd логотип

CVE-2024-27315

почти 2 года назад

An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an error on the database. This error is not properly handled by Apache Superset and may inadvertently surface in the error log of the Alert exposing possibly sensitive data. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-h7r6-8qmm-hj5r

почти 2 года назад

Apache Superset: Improper error handling on alerts

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-27315

An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an error on the database. This error is not properly handled by Apache Superset and may inadvertently surface in the error log of the Alert exposing possibly sensitive data. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-h7r6-8qmm-hj5r

Apache Superset: Improper error handling on alerts

CVSS3: 4.3
0%
Низкий
почти 2 года назад

Уязвимостей на страницу