CVE-2024-24773: Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.
Users are recommended to upgrade to version 3.1.1, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24773?
CVE-2024-24773 has been classified as a significant vulnerability due to its potential to allow authenticated users to exceed their data authorization scope.
How do I fix CVE-2024-24773?
To mitigate CVE-2024-24773, upgrade Apache Superset to version 3.1.1 or higher.
What versions of Apache Superset are affected by CVE-2024-24773?
CVE-2024-24773 affects Apache Superset versions prior to 3.0.4 and between 3.1.0 and 3.1.1.
Who is impacted by CVE-2024-24773?
Authenticated users of Apache Superset prior to version 3.1.1 are impacted by CVE-2024-24773.
Is CVE-2024-24773 a critical vulnerability?
CVE-2024-24773 is considered critical due to its ability to compromise data authorization for users.