First published: Mon Dec 09 2024(Updated: )
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API. issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/apache-superset | >=2.0.0<4.1.0 | 4.1.0 |
Apache Superset | >=2.0.0<4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-53949 is considered a high severity vulnerability due to improper authorization allowing lower privilege users to access sensitive APIs.
To fix CVE-2024-53949, upgrade Apache Superset to version 4.1.0 or later.
CVE-2024-53949 affects Apache Superset versions from 2.0.0 up to but not including 4.1.0.
CVE-2024-53949 allows lower privilege users to utilize the FAB_ADD_SECURITY_API, leading to potential unauthorized access.
No, FAB_ADD_SECURITY_API is disabled by default in Apache Superset versions, but it can still pose a risk if enabled.