https://seclists.org/oss-sec/2024/q4/152: CVE-2024-55633: Apache Superset: SQLLab Improper adonly query validation allows unauthorized write access
Published Dec 12, 2024
·Updated
Affected Software
1 affected component
Apache Superset<4.1.0
Frequently Asked Questions
1
What is the severity of CVE-2024-55633?
CVE-2024-55633 is classified as a high severity vulnerability due to improper authorization allowing unauthorized write access.
2
How do I fix CVE-2024-55633?
To fix CVE-2024-55633, upgrade Apache Superset to version 4.1.0 or later.
3
What versions of Apache Superset are affected by CVE-2024-55633?
CVE-2024-55633 affects all versions of Apache Superset prior to 4.1.0.
4
What type of attacks does CVE-2024-55633 allow?
CVE-2024-55633 allows attackers with SQLLab access to execute unauthorized write operations on PostgreSQL analytic databases.
5
Is there a workaround for CVE-2024-55633 while waiting for an update?
There is no official workaround for CVE-2024-55633; upgrading to a fixed version is the recommended course of action.