Loading HuntDB...

GHSA-92qf-8gh3-gwcm

GitHub Security Advisory

Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions

✓ GitHub Reviewed LOW Has CVE

Advisory Details

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorization. This issue is a follow-up to CVE-2024-39887 with additional disallowed PostgreSQL functions now included: query_to_xml_and_xmlschema, table_to_xml, table_to_xml_and_xmlschema.

This issue affects Apache Superset: <4.1.0.

Users are recommended to upgrade to version 4.1.0, which fixes the issue or add these Postgres functions to the config set DISALLOWED_SQL_FUNCTIONS.

Affected Packages

PyPI apache-superset
Affected versions: 0 (fixed in 4.1.0)

Related CVEs

Key Information

GHSA ID
GHSA-92qf-8gh3-gwcm
Published
December 9, 2024 3:31 PM
Last Modified
July 15, 2025 11:05 PM
CVSS Score
2.5 /10
Primary Ecosystem
PyPI
Primary Package
apache-superset
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 10, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.