Headline
GHSA-jfxj-xf67-x723: Apache Superset SQL injection vulnerability
A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Superset.This issue affects Apache Superset: before 2.1.3, from 3.0.0 before 3.0.2.
Users are recommended to upgrade to version 2.1.3 or 3.0.2, which fixes the issue.
Apache Superset SQL injection vulnerability
Moderate severity GitHub Reviewed Published Dec 19, 2023 to the GitHub Advisory Database • Updated Dec 19, 2023