oss-sec mailing list archives
CVE-2023-32672: Apache Superset: SQL parser edge case bypasses data access authorization
From: Daniel Gaspar <dpgaspar () apache org>
Date: Wed, 06 Sep 2023 09:46:10 +0000
Affected versions: - Apache Superset through 2.1.0 Description: An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability can be exploited by leveraging a SQL parsing vulnerability. Credit: Arnaud Pascal @ Vaadata (finder) References: https://superset.apache.org https://www.cve.org/CVERecord?id=CVE-2023-32672
Current thread:
- CVE-2023-32672: Apache Superset: SQL parser edge case bypasses data access authorization Daniel Gaspar (Sep 06)