Affected versions:

- Apache Superset before 3.0.4
- Apache Superset 3.1.0 before 3.1.1

Description:

A low privilege authenticated user could import an existing dashboard or chart 
that they do not have access to and then modify its metadata, thereby gaining 
ownership of the object. However, it's important to note that access to the 
analytical data of these charts and dashboards would still be subject to 
validation based on data access privileges.

This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.Users 
are recommended to upgrade to version 3.1.1, which fixes the issue.

Credit:

Daniel Vaz Gaspar (remediation developer)
Matt Freyre (finder)

References:

https://superset.apache.org
https://www.cve.org/CVERecord?id=CVE-2024-26016

Reply via email to