PT-2019-12793 · Apache · Apache Incubator Superset

CVE-2019-12414

·

Published

2019-12-16

·

Updated

2023-05-22

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Incubator Superset versions prior to 0.32
Description A user can view database names that he has no access to on a dropdown list in SQLLab.
Recommendations For versions prior to 0.32, update to version 0.32 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12414
GHSA-9C29-9H4M-WG5P
PYSEC-2019-173

Affected Products

Apache Incubator Superset