PT-2024-10308 · Apache · Apache Superset

Bartosz Galaszewski

+1

·

Published

2024-12-09

·

Updated

2025-02-05

·

CVE-2024-53948

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Superset versions prior to 4.1.0
Description The issue is related to the generation of error messages containing analytics metadata information in Apache Superset. This can allow a remote attacker to gain unauthorized access to protected information. Users are recommended to upgrade to a version that fixes the issue.
Recommendations For versions prior to 4.1.0, upgrade to version 4.1.0 to resolve the issue. As a temporary workaround, consider restricting access to error messages that may contain sensitive analytics metadata information until the upgrade is applied.

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-00737
BIT-SUPERSET-2024-53948
CVE-2024-53948
GHSA-2CX9-54HP-R698

Affected Products

Apache Superset