An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: before 2.1.2, from 3.0.0 before 3.0.2.
Users are recommended to upgrade to version 3.0.2 or 2.1.3, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2023-12-19T09:52:13.373Z
Updated: 2024-08-02T22:01:26.049Z
Reserved: 2023-11-30T12:29:59.894Z
Link: CVE-2023-49734
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-12-19T10:15:08.007
Modified: 2024-11-21T08:33:44.893
Link: CVE-2023-49734
Redhat
No data.