Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malicious authenticated user sends an http request with a custom URL.
2021-10-18T15:15:07.730
2024-11-21T06:27:00.463
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4