CVE-2021-37839
published 2022-07-06CVE-2021-37839: Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata…
PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
1.26%
66.1th percentile
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | superset | <= 1.5.1 | — |
| apache_software_foundation | apache_superset | >= Apache Superset < 1.5.1 | 1.5.1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Superset allows authenticated users to access metadata they have no permission to
ghsa·2022-07-07
CVE-2021-37839 [MEDIUM] CWE-273 Apache Superset allows authenticated users to access metadata they have no permission to
Apache Superset allows authenticated users to access metadata they have no permission to
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
OSV
Apache Superset allows authenticated users to access metadata they have no permission to
osv·2022-07-07
CVE-2021-37839 [MEDIUM] Apache Superset allows authenticated users to access metadata they have no permission to
Apache Superset allows authenticated users to access metadata they have no permission to
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-06
Published