CVE-2024-24779
Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to.
Does this matter?
Lower severity and a low EPSS score (0.73%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to unauthorized data. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.73% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- apache/superset
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2024/02/28/6Mailing List, Third Party Advisory
- https://lists.apache.org/thread/xzhz1m5bb9zxhyqgoy4q2d689b3zp4pqMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2024/02/28/6Mailing List, Third Party Advisory
- https://lists.apache.org/thread/xzhz1m5bb9zxhyqgoy4q2d689b3zp4pqMailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.