PT-2025-33273 · Apache · Apache Superset
Beto Dealmeida
+2
·
Published
2025-08-13
·
Updated
2025-08-18
·
CVE-2025-55674
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Superset versions prior to 5.0.0
Description:
A bypass of the
DISALLOWED SQL FUNCTIONS security feature allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions that were intended to be disabled, potentially leading to the disclosure of sensitive database information, such as the software version.Recommendations:
Upgrade to version 5.0.0.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Superset