CVE-2025-55673 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains…
Medium CVSS: 5.3

CVE-2025-55673

When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, to the low-privileged guest user.

This issue affects Apache Superset: before 4.1.3.

Users are recommended to upgrade to version 4.1.3, which fixes the issue.
Vendor
Apache
Product
Superset
CWE
CWE-200
Yayın Tarihi
2025-08-14 14:15:34
Güncelleme
2025-11-04 22:16:30
Source Identifier
security@apache.org
KEV Date Added
-

Kategoriler

Referanslar