oss-sec mailing list archives

CVE-2023-27523: Apache Superset: Improper data permission validation on Jinja templated queries


From: Daniel Gaspar <dpgaspar () apache org>
Date: Wed, 06 Sep 2023 09:17:37 +0000

Affected versions:

- Apache Superset through 2.1.0

Description:

Improper data authorization check on Jinja templated queries in Apache SupersetĀ up to and including 2.1.0 allows for an 
authenticated user to issue queries on database tables they may not have access to.

Credit:

Jingjing Hu (finder)

References:

https://superset.apache.org
https://www.cve.org/CVERecord?id=CVE-2023-27523


Current thread: