PT-2025-23275 · Apache · Apache Superset

Mirakl Security

+1

·

Published

2025-05-30

·

Updated

2025-06-04

·

CVE-2025-48912

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Superset versions prior to 4.1.2
Description An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into sqlExpression fields. This allowed the execution of sub-queries to evade parsing defenses, ultimately granting unauthorized access to data.
Recommendations For Apache Superset versions prior to 4.1.2, update to version 4.1.2 to resolve the issue. As a temporary workaround, consider restricting access to the sqlExpression fields to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06616
BIT-SUPERSET-2025-48912
CVE-2025-48912
GHSA-8W7F-8PR9-XGWJ

Affected Products

Apache Superset