CVE-2019-12413Sensitive Information Exposure in Apache Superset

Severity
5.3MEDIUMNVD
EPSS
0.7%
top 28.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateFeb 26

Description

In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

NVDapache/superset< 0.31

🔴Vulnerability Details

4
OSV
Users able to query database metadata in Apache Superset2020-02-26
GHSA
Users able to query database metadata in Apache Superset2020-02-26
OSV
CVE-2019-12413: In Apache Incubator Superset before 02019-12-16
CVEList
CVE-2019-12413: In Apache Incubator Superset before 02019-12-16
CVE-2019-12413 — Sensitive Information Exposure | cvebase