← back
CVE-2023-27523mediumCWE-863

Apache Superset: Improper data permission validation on Jinja templated queries

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5epss 1.0%
exploitation probability
1.0%top 38% of all CVEs
observed exploitation
nono source reports it
Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N