CVE-2023-27523

Incorrect Authorization in pypi/apache-superset

Identifiers

CVE-2023-27523, GHSA-v594-2c97-hx38

Package Slug

pypi/apache-superset

Vulnerability

Incorrect Authorization

Description

Improper data authorization check on Jinja templated queries in Apache SupersetĀ up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.

Affected Versions

All versions up to 2.1.0

Solution

Upgrade to version 2.1.1 or above.

Last Modified

2023-09-08

source