Affected versions:

- Apache Superset before 3.0.4
- Apache Superset 3.1.0 before 3.1.1

Description:

Apache Superset with custom roles that include `can write on dataset` and 
without all data access permissions, allows for users to create virtual 
datasets to data they don't have access to. These users could then use those 
virtual datasets to get access to unauthorized data.
This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.

Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the 
issue.

Credit:

Daniel Pedro Vaz Gaspar (remediation developer)
@DLT1412 (finder)

References:

https://superset.apache.org
https://www.cve.org/CVERecord?id=CVE-2024-24779

Reply via email to