CVE-2024-28148

CVSS V2 None CVSS V3 None
Description
An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue.
Overview
  • CVE ID
  • CVE-2024-28148
  • Assigner
  • apache
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-05-07T13:33:42.137Z
  • Last Modified Date
  • 2024-06-04T18:03:19.183Z
References
Reference URL Reference Tags
https://lists.apache.org/thread/n27wlbd05oc6bgjh28d5pxzsrrph8dgo vendor-advisory
History
Created Old Value New Value Data Type Notes
2024-06-26 07:35:21 Added to TrackCVE