First published: Wed Jul 06 2022(Updated: )
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/apache-superset | <1.5.1 | 1.5.1 |
Apache Superset | <=1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Apache Superset vulnerability is CVE-2021-37839.
The severity level of CVE-2021-37839 is medium.
CVE-2021-37839 allows authenticated users to access metadata information related to datasets they have no permission on.
The remedy for CVE-2021-37839 is to update to Apache Superset version 1.5.1 or later.
You can find more information about CVE-2021-37839 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-37839), [Apache Mailing List](https://lists.apache.org/thread/pwqyxxmn5gh7cnw3qsp66v0lt4xojt82), [GitHub Commit](https://github.com/apache/superset/commit/2bd89d1705347da5446902a3f65eb8d0a6353503).