Security Advisory

CVE-2024-24773

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-02-28 11:24:58
Last updated 2025-02-13 17:40:22
Assigner apache
CVSS score 4.9
State PUBLISHED

Description

Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1, which fixes the issue.