Apache Superset allows authenticated users to access metadata they have no permission to
Moderate severity
GitHub Reviewed
Published
Jul 7, 2022
to the GitHub Advisory Database
•
Updated Sep 5, 2023
Description
Published by the National Vulnerability Database
Jul 6, 2022
Published to the GitHub Advisory Database
Jul 7, 2022
Reviewed
Jul 15, 2022
Last updated
Sep 5, 2023
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
References