Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
High severity
GitHub Reviewed
Published
Dec 9, 2024
to the GitHub Advisory Database
•
Updated Dec 9, 2024
Description
Published by the National Vulnerability Database
Dec 9, 2024
Published to the GitHub Advisory Database
Dec 9, 2024
Reviewed
Dec 9, 2024
Last updated
Dec 9, 2024
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API.
issue affects Apache Superset: from 2.0.0 before 4.1.0.
Users are recommended to upgrade to version 4.1.0, which fixes the issue.
References