VulnerabilityModified
CVE-2021-37839
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on.
MEDIUM 4.3EPSS 1.30%
Does this matter?
Lower severity and a low EPSS score (1.30%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-273
- Affected
- apache/superset
- Source
- security@apache.org
References
- https://lists.apache.org/thread/pwqyxxmn5gh7cnw3qsp66v0lt4xojt82Mailing List, Third Party Advisory
- https://lists.apache.org/thread/pwqyxxmn5gh7cnw3qsp66v0lt4xojt82Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.