Today > | 2 Medium vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-55633

Dec. 12, 2024, 6:15 p.m.

Product(s) Impacted

Apache Superset

  • before 4.1.0

Description

Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query, enabling its execution. Non postgres analytics database connections and postgres analytics database connections set with a readonly user (advised) are not vulnerable.  This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.

Weaknesses

CWE-285
Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

CWE ID: 285

Date

Published: Dec. 12, 2024, 3:15 p.m.

Last Modified: Dec. 12, 2024, 6:15 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

security@apache.org

References

https://lists.apache.org/ security@apache.org

http://www.openwall.com/ af854a3a-2127-422b-91ae-364da2661108