CVE-2021-37839 – apache-superset
Package
Manager: pip
Name: apache-superset
Vulnerable Version: >=0 <1.5.1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00178 pctl0.39614
Details
Apache Superset allows authenticated users to access metadata they have no permission to Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
Metadata
Created: 2022-07-07T00:00:26Z
Modified: 2023-09-05T20:16:04Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-748r-5r8q-273m/GHSA-748r-5r8q-273m.json
CWE IDs: ["CWE-273"]
Alternative ID: GHSA-748r-5r8q-273m
Finding: F159
Auto approve: 1