Apache Superset: Improper data permission validation on Jinja templated queries
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5epss 1.0%
exploitation probability
1.0%top 38% of all CVEs
observed exploitation
nono source reports it
Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Affected products
Apache Software Foundation · Apache Superset