logo

CVE-2021-37839 apache-superset

Package

Manager: pip
Name: apache-superset
Vulnerable Version: >=0 <1.5.1

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00178 pctl0.39614

Details

Apache Superset allows authenticated users to access metadata they have no permission to Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.

Metadata

Created: 2022-07-07T00:00:26Z
Modified: 2023-09-05T20:16:04Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-748r-5r8q-273m/GHSA-748r-5r8q-273m.json
CWE IDs: ["CWE-273"]
Alternative ID: GHSA-748r-5r8q-273m
Finding: F159
Auto approve: 1