CVE-2024-53949
Dec. 9, 2024, 6:15 p.m.
Tags
Product(s) Impacted
Apache Superset
- 2.0.0 - 4.0.9
Description
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API. issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.
Weaknesses
CWE-285
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE ID: 285Date
Published: Dec. 9, 2024, 2:15 p.m.
Last Modified: Dec. 9, 2024, 6:15 p.m.
Status : Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
security@apache.org