https://seclists.org/oss-sec/2024/q4/149: CVE-2024-53949: Apache Superset: Lower privilege users aable to cate Role when FAB_ADD_SECURITY_API is enabled
Published Dec 9, 2024
·Updated
Affected Software
1 affected component
Apache Superset<4.1.0, >=2.0.0
Frequently Asked Questions
1
What is the severity of CVE-2024-53949?
CVE-2024-53949 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2024-53949?
To fix CVE-2024-53949, upgrade Apache Superset to version 4.1.0 or later.
3
Who is affected by CVE-2024-53949?
CVE-2024-53949 affects users of Apache Superset versions 2.0.0 to 4.0.9 when FAB_ADD_SECURITY_API is enabled.
4
Why is CVE-2024-53949 considered an improper authorization vulnerability?
CVE-2024-53949 is considered an improper authorization vulnerability because it allows lower privilege users to access security-related API functionalities.
5
What applications or services utilize Apache Superset that might be impacted by CVE-2024-53949?
Applications and services that utilize Apache Superset versions 2.0.0 to 4.0.9 with FAB_ADD_SECURITY_API enabled may be impacted by CVE-2024-53949.