CVE-2022-27479

Description

Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
4.979

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-27479 are fixed in Python-apache-superset 1.4.2Windows
Vulnerabilities CVE-2022-27479 are fixed in Python-apache-superset for linux 1.4.2Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234