CVE-2024-24779
Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to unauthorized data. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.
- Affected products
- Apache Superset
- Apache Superset
- ≤ 3.0.4, 3.1.1
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.7% (52th percentile)
- Weakness
- CWE-863
- NVD status
- Modified
- Published
- 2024-02-28
CVE-2024-24779 at NVD
No indexed exploits for CVE-2024-24779 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-24779 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.