First published: Mon Dec 16 2019(Updated: )
In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/apache-superset | <0.32.0 | 0.32.0 |
Apache Superset | <0.32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Apache Superset vulnerability is CVE-2019-12414.
The severity of CVE-2019-12414 is medium (5.3).
The affected software for CVE-2019-12414 is Apache Superset versions up to 0.32.0.
An attacker can exploit CVE-2019-12414 by viewing database names that they have no access to on a dropdown list in SQLLab.
The remedy for CVE-2019-12414 is to upgrade to Apache Superset version 0.32.0 or later.