ZeroHour

CVE-2021-37839

CVSS 3.1
4.3 medium
EPSS
1%p69
Published
()
Modified
Description

Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.

Vendors
apache
Products
superset
Weakness
CWE-273
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.