Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0669 | A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue. |
Github GHSA |
GHSA-m6jm-3v38-76j4 | Apache Superset: Improper Neutralization of custom SQL on embedded context |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 12 Feb 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Wed, 12 Feb 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Feb 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue. | A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue. |
Tue, 31 Dec 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache superset |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache superset |
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-12T09:27:34.758Z
Reserved: 2024-01-30T09:30:45.573Z
Link: CVE-2024-24772
Updated: 2024-08-01T23:28:11.938Z
Status : Modified
Published: 2024-02-28T12:15:47.273
Modified: 2025-02-12T10:15:12.600
Link: CVE-2024-24772
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA