CVE-2024-28148: Apache Superset: Incorrect datasource authorization on explore REST API
An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request. This issue affects Apache Superset before 3.1.2.
Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue.
Other sources
An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2.
Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28148?
CVE-2024-28148 has been classified as a medium severity vulnerability due to its potential impact on unauthorized data access.
How do I fix CVE-2024-28148?
To fix CVE-2024-28148, upgrade Apache Superset to version 3.1.2 or above.
Who is affected by CVE-2024-28148?
CVE-2024-28148 affects authenticated users of Apache Superset versions prior to 3.1.2.
What exploitation vectors exist for CVE-2024-28148?
CVE-2024-28148 can be exploited through targeted REST API requests by users who are not authorized to view certain data.
What versions of Apache Superset are vulnerable to CVE-2024-28148?
Apache Superset versions before 3.1.2 are vulnerable to CVE-2024-28148.