Vulnerability Description
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Superset | <= 1.5.1 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/pwqyxxmn5gh7cnw3qsp66v0lt4xojt82Mailing ListThird Party Advisory
- https://lists.apache.org/thread/pwqyxxmn5gh7cnw3qsp66v0lt4xojt82Mailing ListThird Party Advisory
FAQ
What is CVE-2021-37839?
CVE-2021-37839 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
How severe is CVE-2021-37839?
CVE-2021-37839 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-37839?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Superset.