CVE-2023-27523

Incorrect Authorization in pypi/superset

Identifiers

CVE-2023-27523

Package Slug

pypi/superset

Vulnerability

Incorrect Authorization

Description

Improper data authorization check on Jinja templated queries in Apache SupersetĀ up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.

Affected Versions

All versions up to 2.1.0

Solution

Unfortunately, there is no solution available yet.

Last Modified

2023-09-12

source