QID 150826
Date Published: 2024-03-11
QID 150826: Apache Superset Multiple Vulnerabilities
Apache Superset is an open-source software application for data exploration and data visualization able to handle data at petabyte scale.
Affected versions of Apache Superset has multiple vulnerabilities:
CVE-2024-24772: This vulnerability stems from inadequate neutralization of custom SQL in embedded contexts, potentially leading to unauthorized access or manipulation of sensitive data.
CVE-2024-26016: Insufficient authorization validation during the import of dashboards and charts creates a security loophole, allowing unauthorized users to gain access to or modify critical visualizations.
CVE-2024-24779: In this scenario, the software lacks proper data authorization protocols when creating a new dataset, potentially exposing sensitive information to unauthorized individuals.
CVE-2024-27315: The vulnerability arises from improper error handling in the alert system, introducing the possibility of unintended consequences or unauthorized information disclosure.
CVE-2024-24773: This vulnerability results from inadequate validation of SQL statements, potentially enabling unauthorized access to data through SQL injection attacks.
Affected Versions:
Apache Superset before 3.0.4
Apache Superset 3.1.0 before 3.1.1
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request and checks the response body to confirm if the host is running vulnerable version of Apache Superset.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
For more information regarding this vulnerability please refer:
CVE-2024-24772
CVE-2024-26016
CVE-2024-24779
CVE-2024-27315
CVE-2024-24773
CVEs related to QID 150826
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-24772 |
|
||
| CVE-2024-24773 |
|
||
| CVE-2024-24779 |
|
||
| CVE-2024-26016 |
|
||
| CVE-2024-27315 |
|