NA

CVE-2023-49736

Published: 19/12/2023 Updated: 28/12/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Superset.This issue affects Apache Superset: prior to 2.1.2, from 3.0.0 prior to 3.0.2. Users are recommended to upgrade to version 3.0.2, which fixes the issue.

Vulnerable Product Search on Vulmon Subscribe to Product

apache superset

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2023-49736: Apache Superset: SQL Injection on where_in JINJA macro <!--X-Subject-Header-End--> <!--X-Head-of-Message--> ...