A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to, despite the user having the feature flag "ALLOW_ADHOC_SUBQUERY" disabled (default value). This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2023-01-16T10:14:01.332Z
Updated: 2024-08-03T12:49:43.809Z
Reserved: 2022-09-28T15:13:03.943Z
Link: CVE-2022-41703
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-01-16T11:15:10.303
Modified: 2024-11-21T07:23:41.103
Link: CVE-2022-41703
Redhat
No data.