CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-24779: Apache Superset: Improper data authorization when creating a new dataset

5.0 CVSS

Description

Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to unauthorized data.
This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.

Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.

Classification

CVE ID: CVE-2024-24779

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.0

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Affected Products

Vendor: Apache Software Foundation

Product: Apache Superset

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.11% (probability of being exploited)

EPSS Percentile: 45.08% (scored less or equal to compared to others)

EPSS Date: 2025-03-14 (when was this score calculated)

References

https://lists.apache.org/thread/xzhz1m5bb9zxhyqgoy4q2d689b3zp4pq
http://www.openwall.com/lists/oss-security/2024/02/28/6

Timeline