CVE-2022-27479
published 2022-04-13CVE-2022-27479: Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.79%
84.8th percentile
Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | superset | < 1.4.2 | 1.4.2 |
| apache_software_foundation | apache_superset | >= unspecified < 1.4.2 | 1.4.2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
SQL injection in apache-superset
osv·2022-04-14
CVE-2022-27479 [CRITICAL] SQL injection in apache-superset
SQL injection in apache-superset
Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.
GHSA
SQL injection in apache-superset
ghsa·2022-04-14
CVE-2022-27479 [CRITICAL] CWE-89 SQL injection in apache-superset
SQL injection in apache-superset
Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.
OSV
CVE-2022-27479: Apache Superset before 1
osv·2022-04-13
CVE-2022-27479 CVE-2022-27479: Apache Superset before 1
Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/04/13/3https://lists.apache.org/thread/94th50j5d0y2fw7ysx0g7w3t6jk3z7q6https://lists.apache.org/thread/ztb9b6jd9rngoxwvq8r4fhpp401o613yhttp://www.openwall.com/lists/oss-security/2022/04/13/3https://lists.apache.org/thread/94th50j5d0y2fw7ysx0g7w3t6jk3z7q6https://lists.apache.org/thread/ztb9b6jd9rngoxwvq8r4fhpp401o613y
2022-04-13
Published