issue affects Apache Superset: from 2.0.0 before 4.1.0.
Users are recommended to upgrade to version 4.1.0, which fixes the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3416 | Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API. issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue. |
Github GHSA |
GHSA-35fc-9hrj-3585 | Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled |
Wed, 12 Feb 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Tue, 11 Feb 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 | |
| Metrics |
cvssV3_1
|
Mon, 09 Dec 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 09 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache superset |
|
| CPEs | cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache superset |
|
| Metrics |
ssvc
|
Mon, 09 Dec 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API. issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue. | |
| Title | Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-12T09:34:57.804Z
Reserved: 2024-11-25T11:35:43.585Z
Link: CVE-2024-53949
Updated: 2024-12-09T18:03:43.157Z
Status : Modified
Published: 2024-12-09T14:15:12.647
Modified: 2025-02-12T10:15:13.790
Link: CVE-2024-53949
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA