Apache Superset has incorrect authorization check
Moderate severity
GitHub Reviewed
Published
Sep 6, 2023
to the GitHub Advisory Database
•
Updated Nov 6, 2023
Description
Published by the National Vulnerability Database
Sep 6, 2023
Published to the GitHub Advisory Database
Sep 6, 2023
Reviewed
Sep 7, 2023
Last updated
Nov 6, 2023
An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability can be exploited by leveraging a SQL parsing vulnerability.
References