Skip to content
Apache SupersetGHSA-wh73-hpcg-v32j

SQL injection in apache-superset

Critical9.8CVE-2022-27479 · Published Apr 14, 2022 · updated Feb 5, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 1.4.21.4.2
Details and references

Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-89
Also known as
BIT-superset-2022-27479, CVE-2022-27479, PYSEC-2022-188

More Apache Superset advisories

All Apache Superset
DateAdvisory
May 242022Apache Superset SQL Injection when template processing is enabled
CVE-2021-41971High8.8fixed in 1.3.1
May 242022Apache Superset Cross-site Scripting (XSS) vulnerability on the Explore page
CVE-2021-32609Medium5.4fixed in 1.2.0
May 242022Apache Superset allowed for database connections password leak for authenticated users
CVE-2021-41972High6.5fixed in 1.3.2
May 242022Improper Encoding or Escaping of Output in Apache Superset
CVE-2021-42250High6.5fixed in 1.3.2
May 242022Apache Superset OS Command Injection
CVE-2020-13948High8.8fixed in 0.37.1
May 242022Apache Superset Stored XSS on Dashboard markdown
CVE-2021-27907Medium5.4fixed in 0.38.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.