Apache SupersetGHSA-fxjm-wvj9-9c39
Information disclosure in Apache Superset
Medium6.5CVE-2020-1932 · Published Feb 26, 2020 · updated Feb 5, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | >= 0.34.0, < 0.35.2 | 0.35.2 |
Details and references
An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- BIT-superset-2020-1932, CVE-2020-1932, PYSEC-2020-224
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 262020 | Users can view database names in Apache Superset CVE-2019-12414Medium5.3fixed in 0.32.0 | Medium5.3 | 0.32.0 |
| Feb 262020 | Users able to query database metadata in Apache Superset CVE-2019-12413Medium5.3fixed in 0.31.0 | Medium5.3 | 0.31.0 |
| Apr 302021 | Plaintext password leak in Apache Superset CVE-2020-13952High8.1fixed in 0.37.2 | High8.1 | 0.37.2 |
| Oct 62021 | Open Redirect in Apache Superset CVE-2021-28125Medium6.1fixed in 1.1.0 | Medium6.1 | 1.1.0 |
| Feb 22022 | Insufficiently Protected Credentials in Apache Superset CVE-2021-44451High6.5fixed in 1.4.0 | High6.5 | 1.4.0 |
| Apr 142022 | SQL injection in apache-superset CVE-2022-27479Critical9.8fixed in 1.4.2 | Critical9.8 | 1.4.2 |