First published: Tue May 07 2024(Updated: )
An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request. This issue affects Apache Superset before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/apache-superset | <3.1.2 | 3.1.2 |
Apache Superset | <4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28148 has been classified as a medium severity vulnerability due to its potential impact on unauthorized data access.
To fix CVE-2024-28148, upgrade Apache Superset to version 3.1.2 or above.
CVE-2024-28148 affects authenticated users of Apache Superset versions prior to 3.1.2.
CVE-2024-28148 can be exploited through targeted REST API requests by users who are not authorized to view certain data.
Apache Superset versions before 3.1.2 are vulnerable to CVE-2024-28148.