Improper Access Control in Apache Superset
CVE-2019-12413
5.3MEDIUM
What is CVE-2019-12413?
A vulnerability in Apache Superset prior to version 0.31 allows users to exploit improperly restricted access control features. By crafting complex queries, unauthorized individuals could query database metadata information from databases they should not have access to. This could lead to the exposure of sensitive information and potential manipulation of data, emphasizing the importance of applying proper access restrictions to safeguard database integrity.
Affected Version(s)
Apache Incubator Superset Apache Incubator Superset 0.0.0 to 0.29.0