A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to, despite the user having the feature flag "ALLOW_ADHOC_SUBQUERY" disabled (default value). This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.


Advisories
Source ID Title
EUVD EUVD EUVD-2023-0451 A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to, despite the user having the feature flag "ALLOW_ADHOC_SUBQUERY" disabled (default value). This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Github GHSA Github GHSA GHSA-cxvp-3frm-3876 Apache Superset's SQL Alchemy connector vulnerable to SQL Injection
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 08 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-04-08T20:33:49.417Z

Reserved: 2022-09-28T15:13:03.943Z

Link: CVE-2022-41703

cve-icon Vulnrichment

Updated: 2024-08-03T12:49:43.809Z

cve-icon NVD

Status : Modified

Published: 2023-01-16T11:15:10.303

Modified: 2025-04-08T21:15:44.640

Link: CVE-2022-41703

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.