CVE-2024-28148

MEDIUM4.3EPSS 0.08%

Apache Superset Incorrect Authorization vulnerability

發布日:2024/5/7修改日:2025/2/5
也稱為:GHSA-299q-3p96-5898BIT-superset-2024-28148

描述

An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request. This issue affects Apache Superset before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

參考連結(3)