ZeroHour

CVE-2022-27479

CVSS 3.1
9.8 critical
EPSS
3%p86
Published
()
Modified
Description

Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.

Vendors
apache
Products
superset
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.