Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-32672


An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability can be exploited by leveraging a SQL parsing vulnerability.


Published

2023-09-06T14:15:10.297

Last Modified

2024-11-21T08:03:49.267

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache superset ≤ 2.1.0 Yes

References