Lucene search

K
osvGoogleOSV:PYSEC-2021-378
HistoryOct 18, 2021 - 3:15 p.m.

PYSEC-2021-378

2021-10-1815:15:00
Google
osv.dev
11
apache
superset
sql injection
vulnerability
http request

EPSS

0.001

Percentile

34.2%

Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malicious authenticated user sends an http request with a custom URL.

EPSS

0.001

Percentile

34.2%

Related for OSV:PYSEC-2021-378