PT-2021-23459 · Apache · Apache Superset

·

CVE-2021-41971

·

Published

2021-10-18

·

Updated

2025-02-05

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Superset versions up to and including 1.3.0
Description The issue allows SQL injection when a malicious authenticated user sends an HTTP request with a custom URL, but only when Apache Superset is configured with ENABLE TEMPLATE PROCESSING enabled, which is disabled by default.
Recommendations For Apache Superset versions up to and including 1.3.0, consider disabling the ENABLE TEMPLATE PROCESSING configuration to prevent SQL injection attacks until a patch is available.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-SUPERSET-2021-41971
CVE-2021-41971
GHSA-PG8M-4P8J-2P56
PYSEC-2021-378

Affected Products

Apache Superset