apache-superset@3.1.0rc1 vulnerabilities
A modern, enterprise-ready business intelligence web application
-
latest version
4.0.0
-
latest non vulnerable version
-
first published
5 years ago
-
latest version published
a month ago
-
licenses detected
- [0,)
Direct Vulnerabilities
Known vulnerabilities in the apache-superset package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File. A user with Alerts & Reports privileges to create Alerts can cause a malicious SQL statement to throw and error and have its contents logged. Thee error is not properly handled and can expose sensitive data. How to fix Insertion of Sensitive Information into Log File? Upgrade |
[,3.0.4)
[3.1.0rc1,3.1.1)
|
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Improper Authorization when creating a new virtual dataset using custom roles that include "can write on dataset". This allows users to access data in other datasets to which they do not otherwise have access. How to fix Improper Authorization? Upgrade |
[,3.0.4)
[3.1.0rc1,3.1.1)
|
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Incorrect Authorization when processing nested SQL statements in SQLLab, allowing a user to access unauthorized data. How to fix Incorrect Authorization? Upgrade |
[,3.0.4)
[3.1.0rc1,3.1.1)
|
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to SQL Injection in an embedded context, allowing a guest user to expose information from the analytics database via chart data REST API call. How to fix SQL Injection? Upgrade |
[,3.0.4)
[3.1.0rc1,3.1.1)
|