oss-sec mailing list archives

CVE-2023-32672: Apache Superset: SQL parser edge case bypasses data access authorization


From: Daniel Gaspar <dpgaspar () apache org>
Date: Wed, 06 Sep 2023 09:46:10 +0000

Affected versions:

- Apache Superset through 2.1.0

Description:

An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability 
allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability 
can be exploited by leveraging a SQL parsing vulnerability.

Credit:

Arnaud Pascal @ Vaadata (finder)

References:

https://superset.apache.org
https://www.cve.org/CVERecord?id=CVE-2023-32672


Current thread: