apache-superset@4.0.0rc1 vulnerabilities

A modern, enterprise-ready business intelligence web application

Direct Vulnerabilities

Known vulnerabilities in the apache-superset package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • L
SQL Injection

apache-superset is a modern, enterprise-ready business intelligence web application.

Affected versions of this package are vulnerable to SQL Injection by using engine-specific functions that are not adequately checked. This is only exploitable if the DISALLOWED_SQL_FUNCTIONS configuration is not set to disallow critical functions.

How to fix SQL Injection?

Upgrade apache-superset to version 4.0.2 or higher.

[,4.0.2)
  • M
Incorrect Authorization

apache-superset is a modern, enterprise-ready business intelligence web application.

Affected versions of this package are vulnerable to Incorrect Authorization due to the improper handling of REST API requests. An authenticated attacker can access unauthorized metadata that they are not authorized to view by submitting a targeted request.

How to fix Incorrect Authorization?

Upgrade apache-superset to version 3.1.2, 4.0.0rc2 or higher.

[,3.1.2) [4.0.0rc1,4.0.0rc2)