SQL injection vulnerability in chart data API
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 2.9%
exploitation probability
2.9%top 14% of all CVEs
observed exploitation
nono source reports it
Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.
Affected products
Apache Software Foundation · Apache Superset