apache-superset@3.1.2 vulnerabilities
A modern, enterprise-ready business intelligence web application
-
latest version
4.1.0
-
latest non vulnerable version
-
first published
5 years ago
-
latest version published
7 days ago
-
licenses detected
- [0,)
Direct Vulnerabilities
Known vulnerabilities in the apache-superset package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to SQL Injection by using engine-specific functions that are not adequately checked. This is only exploitable if the How to fix SQL Injection? Upgrade |
[,4.0.2)
|
apache-superset is a modern, enterprise-ready business intelligence web application. Affected versions of this package are vulnerable to Arbitrary File Read by allowing an authenticated attacker to create a MariaDB connection with Note: This is only exploitable if both the MariaDB server and the local mysql client on the web server are set to allow for local infile. How to fix Arbitrary File Read? Upgrade |
[,3.1.3)
[4.0.0,4.0.1)
|