CVE-2021-37839: Improper access to dataset metadata information
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Apache Superset vulnerability?
The vulnerability ID for this Apache Superset vulnerability is CVE-2021-37839.
What is the severity level of CVE-2021-37839?
The severity level of CVE-2021-37839 is medium.
How does CVE-2021-37839 affect Apache Superset?
CVE-2021-37839 allows authenticated users to access metadata information related to datasets they have no permission on.
What is the remedy for CVE-2021-37839?
The remedy for CVE-2021-37839 is to update to Apache Superset version 1.5.1 or later.
Where can I find more information about CVE-2021-37839?
You can find more information about CVE-2021-37839 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-37839), [Apache Mailing List](https://lists.apache.org/thread/pwqyxxmn5gh7cnw3qsp66v0lt4xojt82), [GitHub Commit](https://github.com/apache/superset/commit/2bd89d1705347da5446902a3f65eb8d0a6353503).