CRITICAL9.8CVE-2023-27524⚠ KEVApache Superset: Session validation vulnerability when using provided default SECRET_KEY from 0, < 2.0.2
CRITICAL9.8CVE-2024-39887Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions from 0, < 4.1.1
CRITICAL9.8CVE-2022-27479SQL injection vulnerability in chart data API from 0, < 1.4.2
HIGH8.8Apache Superset: SQL Injection on where_in JINJA macro
from 0, < 2.1.2, >= 3.0.0, < 3.0.2
HIGH8.8Apache Superset: Privilege escalation with default examples database
from 0, < 2.1.2
HIGH8.8Apache Superset: Cross Site Request Forgery (CSRF) on accept, request access API
from 0, < 1.5.3, >= 2.0.0, < 2.0.1
HIGH8.8Apache Superset OS Command Injection
from 0, < 0.37.1
HIGH8.8Possible SQL Injection when template processing is enabled
from 0, < 1.3.1
HIGH8.1Plaintext password leak in Apache Superset
from 0, < 0.37.2
MEDIUM6.6Apache Superset: Metadata db write access can lead to remote code execution
>= 1.5.0, < 2.1.1
MEDIUM6.5Apache Superset: Allows for uncontrolled resource consumption via a ZIP bomb (version range fix for CVE-2023-46104)
from 0, < 4.1.1
MEDIUM6.5Apache Superset: Improper data authorization when creating a new dataset
from 0, < 4.1.1
MEDIUM6.5Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
from 0, < 4.1.1
MEDIUM6.5Apache Superset: Allows for uncontrolled resource consumption via a ZIP bomb
from 0, < 2.1.3, >= 3.0.0, < 3.0.1
MEDIUM6.5Apache Superset: Privilege Escalation Vulnerability
from 0, < 2.1.2, >= 3.0.0, < 3.0.2
MEDIUM6.5Apache Superset: Lack of rate limiting allows for possible denial of service
from 0, < 3.0.0
MEDIUM6.5Apache Superset: Possible Unauthorized Registration of SQLite Database Connections
from 0, < 2.1.1
MEDIUM6.5Apache Superset: Database connection password leak
>= 1.3.0, < 2.0.2
MEDIUM6.5Apache Superset: Possible SSRF on import datasets
from 0, < 2.0.2
MEDIUM6.5Possible log injection
from 0, < 1.3.2
MEDIUM6.5Credentials leak
from 0, < 1.3.2
MEDIUM6.5API sensitive information leak
from 0, < 1.3.3
MEDIUM6.5Information disclosure in Apache Superset
>= 0.34.0, < 0.34.1, >= 0.34.1, < 0.34.2, >= 0.35.0, < 0.35.1, >= 0.35.1, < 0.35.2
MEDIUM6.1Apache Superset Open Redirect
from 0, < 1.0.2
MEDIUM5.4Apache Superset: Improper authorization validation on dashboards and charts import
from 0, < 4.1.1
MEDIUM5.4Apache Superset: Open Redirect Vulnerability
from 0, < 3.0.0
MEDIUM5.4Apache Superset: Stored XSS on API endpoint
from 0, < 2.1.2
MEDIUM5.4Apache Superset: Improper API permission for low privilege users
from 0, < 2.1.1
MEDIUM5.4Apache Superset: Improper API permission for low privilege users allows for SSRF
from 0, < 2.1.1
MEDIUM5.4Apache Superset: SQL injection vulnerability in adhoc clauses
from 0, < 1.5.3, >= 2.0.0, < 2.0.1
MEDIUM5.4Apache Superset: Cross-Site Scripting on dashboards
from 0, < 1.5.3, >= 2.0.0, < 2.0.1
MEDIUM5.4Apache Superset: Cross-Site Scripting vulnerability on upload forms
from 0, < 1.5.3, >= 2.0.0, < 2.0.1
MEDIUM5.4Apache Superset: Improper rendering of user input
from 0, < 1.5.3, >= 2.0.0, < 2.0.1
MEDIUM5.4Apache Superset: Open Redirect Vulnerability
from 0, < 1.5.3, >= 2.0.0, < 2.0.1
MEDIUM5.4Apache Superset stored XSS on Dashboard markdown
from 0, < 0.38.1
MEDIUM5.4XSS vulnerability on Explore page
from 0, < 1.1.1
MEDIUM5.3Apache Superset: Server arbitrary file read
from 0, < 4.1.1
MEDIUM5.3Apache Superset: Dashboard metadata information leak
from 0, < 1.5.3, >= 2.0.0, < 2.0.1
MEDIUM4.3Apache Superset: Incorrect datasource authorization on explore REST API
from 0, < 4.1.1
MEDIUM4.3Apache Superset: Improper Neutralisation of custom SQL on embedded context
from 0, < 4.1.1
MEDIUM4.3Apache Superset: Improper error handling on alerts
from 0, < 4.1.1
MEDIUM4.3Apache Superset: Sensitive information disclosure on db connection details
from 0, < 3.0.0
MEDIUM4.3Apache Superset: Unnecessary read permissions within the Gamma role
from 0, < 2.1.1
MEDIUM4.3Apache Superset: SQL parser edge case bypasses data access authorization
from 0, < 2.1.1
MEDIUM4.3Apache Superset: Improper data permission validation on Jinja templated queries
from 0, < 2.1.1
MEDIUM4.3Apache Superset: Improper Authorization check on import charts
from 0, < 2.1.1
MEDIUM4.3Apache Superset: Stack traces enabled by default
from 0, < 2.1.1
MEDIUM4.3Apache Superset: Incorrect default permissions for Gamma role
from 0, < 2.0.2
MEDIUM4.3Improper access to dataset metadata information
from 0, < 1.5.2
—Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering
from 0, < 4.1.2
—Apache Superset: Improper Neutralization of Special Elements used in a SQL Command
from 0, < 6.0.0
—Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass
from 0, < 6.0.0
—Apache Superset: Sensitive Data Exposure via REST API (disabled by default)
from 0, < 6.0.0
—Apache Superset: SQLLab Read-Only Bypass on PostgreSQL
from 0, < 6.0.0
—Apache Superset: Stored XSS on charts metadata
from 0, < 5.0.0
—Apache Superset: Metadata exposure in embedded charts
from 0, < 4.1.3
—Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions
from 0, < 5.0.0
—Apache Superset: Incorrect datasource authorization on REST API
from 0, < 5.0.0
—Apache Superset: Improper authorization bypass on row level security via SQL Injection
from 0, < 4.1.2
—Apache Superset: Incorrect authorization leading to resource ownership takeover
from 0, < 4.1.2
—Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
from 0, < 4.1.1
—Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
from 0, < 4.1.1
—Apache Superset: Error verbosity exposes metadata in analytics databases
from 0, < 4.1.1
—Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
>= 2.0.0, < 4.1.1