First published: Mon Jan 16 2023(Updated: )
A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to, despite the user having the feature flag "ALLOW_ADHOC_SUBQUERY" disabled (default value). This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Superset | <=1.5.2 | |
Apache Superset | =2.0.0 | |
Apache Superset | =2.0.0-rc1 | |
Apache Superset | =2.0.0-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41703 is a vulnerability in the SQL Alchemy connector of Apache Superset that allows an authenticated user with read access to a specific database to add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to.
The affected software is Apache Superset version 1.5.2, 2.0.0, 2.0.0-rc1, and 2.0.0-rc2.
The severity of CVE-2022-41703 is medium with a CVSS score of 5.4.
To fix the vulnerability, upgrade Apache Superset to a version that is not affected, such as version 1.5.3 or later.
You can find more information about CVE-2022-41703 at the following link: https://lists.apache.org/thread/g7jjw0okxjk5y57pbbxy19ydw42kqcos