CRITICAL9.8CVE-2022-27479SQL injection vulnerability in chart data API from 0, < 1.4.2
CRITICAL9.8CVE-2022-27479SQL injection vulnerability in chart data API from 0, < 1.4.2
CRITICAL9.6CVE-2023-49657Apache Superset: Stored XSS in Dashboard Title and Chart Title from 0, < 3.0.3
HIGH8.8Apache Superset OS Command Injection
from 0, < 0.37.1
HIGH8.8Apache Superset OS Command Injection
from 0, < 0.37.1
HIGH8.8Possible SQL Injection when template processing is enabled
from 0, < 1.3.1
HIGH8.8Possible SQL Injection when template processing is enabled
from 0, < 1.3.1
HIGH8.1Plaintext password leak in Apache Superset
from 0, < 0.37.2
HIGH8.1Plaintext password leak in Apache Superset
from 0, < 0.37.2
MEDIUM6.5Possible log injection
from 0, < 1.3.2
MEDIUM6.5Possible log injection
from 0, < 1.3.2
MEDIUM6.5Credentials leak
from 0, < 1.3.2
MEDIUM6.5Credentials leak
from 0, < 1.3.2
MEDIUM6.5API sensitive information leak
from 0, < 1.4.0
MEDIUM6.5API sensitive information leak
from 0, < 1.4.0
MEDIUM6.5Information disclosure in Apache Superset
>= 0.34.0, < 0.35.2
MEDIUM6.5Information disclosure in Apache Superset
from 0, < 0.35.2
MEDIUM6.1Apache Superset Open Redirect
from 0, < 1.1.0
MEDIUM6.1Apache Superset Open Redirect
from 0, < 1.1.0
MEDIUM5.4Apache Superset stored XSS on Dashboard markdown
from 0, < 0.38.1
MEDIUM5.4Apache Superset stored XSS on Dashboard markdown
from 0, < 0.38.1
MEDIUM5.4XSS vulnerability on Explore page
from 0, < 1.2.0
MEDIUM5.4XSS vulnerability on Explore page
from 0, < 1.2.0
MEDIUM5.3Users able to query database metadata in Apache Superset
from 0, < 0.31.0
MEDIUM5.3Users able to query database metadata in Apache Superset
from 0, < 0.31
MEDIUM5.3Users can view database names in Apache Superset
from 0, < 0.32.0
MEDIUM5.3Users can view database names in Apache Superset
from 0, < 0.32
—Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass
from 0, < 6.0.0
—Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering
from 0, < 4.1.2
—Apache Superset: Improper Neutralization of Special Elements used in a SQL Command
from 0, < 6.0.0
—Apache Superset: Sensitive Data Exposure via REST API (disabled by default)
from 0, < 6.0.0
—Apache Superset: SQLLab Read-Only Bypass on PostgreSQL
from 0, < 6.0.0
—Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass
from 0, < 6.0.0
—Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering
from 0, < 4.1.2
—Apache Superset: Improper Neutralization of Special Elements used in a SQL Command
from 0, < 6.0.0
—Apache Superset: Sensitive Data Exposure via REST API (disabled by default)
from 0, < 6.0.0
—Apache Superset: SQLLab Read-Only Bypass on PostgreSQL
from 0, < 6.0.0