First published: Wed Apr 13 2022(Updated: )
Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/apache-superset | <1.4.2 | 1.4.2 |
Apache Superset | <1.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27479 is a SQL injection vulnerability in Apache Superset before version 1.4.2.
CVE-2022-27479 has a severity rating of 9.8 (critical).
To fix CVE-2022-27479, users should update Apache Superset to version 1.4.2 or higher.
The affected software for CVE-2022-27479 is Apache Superset versions prior to 1.4.2.
The CWE ID for CVE-2022-27479 is CWE-89 (SQL Injection).