Vulnerability identifier: #VU71201
Vulnerability risk: Low
CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-264
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Apache Superset
Web applications /
Other software
Vendor: Apache Foundation
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to improper access access restrictions within the SQL Alchemy connector. A remote user with with read access to a specific database can add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to, despite the user having the feature flag "ALLOW_ADHOC_SUBQUERY" disabled (default value).
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Apache Superset: 2.0.0, 1.5.0 - 1.5.2
External links
http://seclists.org/oss-sec/2023/q1/29
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.