PT-2021-23459 · Apache · Apache Superset

Kevin Kusnardi

·

Published

2021-10-18

·

Updated

2025-02-05

·

CVE-2021-41971

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Superset versions up to and including 1.3.0
Description The issue allows SQL injection when a malicious authenticated user sends an HTTP request with a custom URL, but only when Apache Superset is configured with ENABLE TEMPLATE PROCESSING enabled, which is disabled by default.
Recommendations For Apache Superset versions up to and including 1.3.0, consider disabling the ENABLE TEMPLATE PROCESSING configuration to prevent SQL injection attacks until a patch is available.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BIT-SUPERSET-2021-41971
CVE-2021-41971
GHSA-PG8M-4P8J-2P56
PYSEC-2021-378

Affected Products

Apache Superset