logo

CVE-2024-24779 apache-superset

Package

Manager: pip
Name: apache-superset
Vulnerable Version: >=0 <3.0.4 || >=3.1.0 <3.1.1

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00119 pctl0.31461

Details

Apache Superset: Improper data authorization when creating a new dataset Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to unauthorized data. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.

Metadata

Created: 2024-02-28T12:30:27Z
Modified: 2025-02-13T19:10:00Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-wr6g-9wcr-cmqj/GHSA-wr6g-9wcr-cmqj.json
CWE IDs: ["CWE-863"]
Alternative ID: GHSA-wr6g-9wcr-cmqj
Finding: F006
Auto approve: 1