Impact
The vulnerability is an improper neutralization of special elements used in a SQL command (SQL injection). It allows an authenticated user with read access to execute error‑based SQL injection through the sqlExpression or where parameters in Apache Superset. Attackers can read data stored in the database, potentially exposing confidential information. The flaw is classified as CWE‑89 and requires authentication and read‑only privileges to operate.
Affected Systems
All deployments of Apache Superset provided by the Apache Software Foundation running versions prior to 6.0.0 are affected. The vulnerability applies to every release version before 6.0.0, with no further granularity specified in the advisory.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, primarily impacting confidentiality. The EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog and no public exploits have been reported. Because the flaw requires authenticated access but only read privileges, the overall risk to the system is moderate but still warrants timely mitigation to protect sensitive data.
OpenCVE Enrichment
Github GHSA