Lucene search

K
cvelistApacheCVELIST:CVE-2021-37839
HistoryJul 06, 2022 - 12:35 p.m.

CVE-2021-37839 Improper access to dataset metadata information

2022-07-0612:35:10
CWE-273
apache
www.cve.org
4
cve-2021-37839
apache superset
dataset metadata

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

29.4%

Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.

CNA Affected

[
  {
    "product": "Apache Superset",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThan": "1.5.1",
        "status": "affected",
        "version": "Apache Superset",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

29.4%

Related for CVELIST:CVE-2021-37839