BIT-superset-2024-26016

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/superset/BIT-superset-2024-26016.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-superset-2024-26016
Aliases
Published
2025-02-05T07:25:54.594Z
Modified
2025-05-20T10:02:07.006Z
Summary
Apache Superset: Improper authorization validation on dashboards and charts import
Details

A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object. However, it's important to note that access to the analytical data of these charts and dashboards would still be subject to validation based on data access privileges.

This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.Users are recommended to upgrade to version 3.1.1, which fixes the issue.

Database specific
{
    "cpes": [
        "cpe:2.3:a:apache:superset:*:*:*:*:*:python:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / superset

Package

Name
superset
Purl
pkg:bitnami/superset

Severity

  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.1