Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-95ch-p3gw-23qg: Apache Superset has incorrect authorization check

An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability can be exploited by leveraging a SQL parsing vulnerability.

ghsa
#sql#vulnerability#apache#git#auth

Apache Superset has incorrect authorization check

Moderate severity GitHub Reviewed Published Sep 6, 2023 to the GitHub Advisory Database • Updated Sep 7, 2023

Related news

CVE-2023-32672

An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability can be exploited by leveraging a SQL parsing vulnerability.