https://seclists.org/oss-sec/2024/q2/216: CVE-2024-28148: Apache Superset: Incorrect datasource authorization on explore REST API
Published May 7, 2024
·Updated
Affected Software
1 affected component
Apache Superset
Frequently Asked Questions
1
What is the severity of CVE-2024-28148?
CVE-2024-28148 has been assigned a medium severity level that indicates a potential risk of unauthorized access to sensitive data.
2
How do I fix CVE-2024-28148?
To fix CVE-2024-28148, upgrade Apache Superset to the latest version where the vulnerability has been patched.
3
What is the impact of CVE-2024-28148?
CVE-2024-28148 could allow unauthorized users to access and explore data sources they should not have permissions for.
4
Who is affected by CVE-2024-28148?
Organizations using vulnerable versions of Apache Superset for data visualization and analytics are affected by CVE-2024-28148.
5
When was CVE-2024-28148 published?
CVE-2024-28148 was published on May 7, 2024.