QID 997561
Date Published: 2024-02-29
QID 997561: Python (Pip) Security Update for apache-superset (GHSA-wr6g-9wcr-cmqj)
Apache Superset with custom roles that include can write on dataset and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to unauthorized data. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-wr6g-9wcr-cmqj for updates and patch information.
Vendor References
- GHSA-wr6g-9wcr-cmqj -
github.com/advisories/GHSA-wr6g-9wcr-cmqj
CVEs related to QID 997561
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wr6g-9wcr-cmqj | apache-superset |
|