QID 150826

Date Published: 2024-03-11

QID 150826: Apache Superset Multiple Vulnerabilities

Apache Superset is an open-source software application for data exploration and data visualization able to handle data at petabyte scale.

Affected versions of Apache Superset has multiple vulnerabilities:
CVE-2024-24772: This vulnerability stems from inadequate neutralization of custom SQL in embedded contexts, potentially leading to unauthorized access or manipulation of sensitive data.

CVE-2024-26016: Insufficient authorization validation during the import of dashboards and charts creates a security loophole, allowing unauthorized users to gain access to or modify critical visualizations.

CVE-2024-24779: In this scenario, the software lacks proper data authorization protocols when creating a new dataset, potentially exposing sensitive information to unauthorized individuals.

CVE-2024-27315: The vulnerability arises from improper error handling in the alert system, introducing the possibility of unintended consequences or unauthorized information disclosure.

CVE-2024-24773: This vulnerability results from inadequate validation of SQL statements, potentially enabling unauthorized access to data through SQL injection attacks.

Affected Versions:
Apache Superset before 3.0.4
Apache Superset 3.1.0 before 3.1.1

QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request and checks the response body to confirm if the host is running vulnerable version of Apache Superset.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to upgrade to Apache Superset to latest version to remediate this vulnerability.
    For more information regarding this vulnerability please refer:
    CVE-2024-24772
    CVE-2024-26016
    CVE-2024-24779
    CVE-2024-27315
    CVE-2024-24773
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    CVE-2024-24772 URL Logo lists.apache.org/thread/gfl3ckwy6y9tpz9jmpv62orh2q346sn5
    CVE-2024-24773 URL Logo lists.apache.org/thread/h66fy6nj41cfx07zh7l552w6dmtjh501
    CVE-2024-24779 URL Logo lists.apache.org/thread/xzhz1m5bb9zxhyqgoy4q2d689b3zp4pq
    CVE-2024-26016 URL Logo lists.apache.org/thread/76v1jjcylgk4p3m0258qr359ook3vl8s
    CVE-2024-27315 URL Logo lists.apache.org/thread/qcwbx7q2s3ynsd405895bx3wcwq32j7z

    © CVE.report 2026

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report