First published: Mon Dec 16 2019(Updated: )
In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Superset | <0.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12413 is a vulnerability in Apache Incubator Superset before version 0.31.0 that allows a user to query database metadata information from a database they have no access to.
The severity of CVE-2019-12413 is medium with a CVSS score of 5.3.
You are affected by CVE-2019-12413 if you are using Apache Incubator Superset before version 0.31.0.
To fix CVE-2019-12413, ensure that you are using version 0.31.0 or later of Apache Incubator Superset.
You can find more information about CVE-2019-12413 on the NIST NVD website, the Apache Superset mailing list, and the Snyk vulnerability database.