Skip to content
Apache SupersetGHSA-p5w7-qmq6-pmjr

Users able to query database metadata in Apache Superset

Medium5.3CVE-2019-12413 · Published Feb 26, 2020 · updated Sep 5, 2024

In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 0.31.00.31.0
Details and references

More Apache Superset advisories

All Apache Superset
Advisory
SQL injection in apache-superset
Critical9.8Apr 14, 2022
Insufficiently Protected Credentials in Apache Superset
High6.5Feb 2, 2022
Open Redirect in Apache Superset
Medium6.1Oct 6, 2021
Plaintext password leak in Apache Superset
High8.1Apr 30, 2021
Users can view database names in Apache Superset
Medium5.3Feb 26, 2020
Information disclosure in Apache Superset
Medium6.5Feb 26, 2020

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.