Description
A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to, despite the user having the feature flag "ALLOW_ADHOC_SUBQUERY" disabled (default value). This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0451 | A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to, despite the user having the feature flag "ALLOW_ADHOC_SUBQUERY" disabled (default value). This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0. |
Github GHSA |
GHSA-cxvp-3frm-3876 | Apache Superset's SQL Alchemy connector vulnerable to SQL Injection |
References
History
Tue, 08 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-04-08T20:33:49.417Z
Reserved: 2022-09-28T15:13:03.943Z
Link: CVE-2022-41703
Updated: 2024-08-03T12:49:43.809Z
Status : Modified
Published: 2023-01-16T11:15:10.303
Modified: 2025-04-08T21:15:44.640
Link: CVE-2022-41703
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA