CVE-2022-27479

CRITICAL

Apache Superset < 1.4.2 - SQL Injection in Chart Data Requests

Title source: llm
STIX 2.1

Description

Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.

References (3)

Core 3
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/04/13/3

Scores

CVSS v3 9.8
EPSS 0.0433
EPSS Percentile 89.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
apache/superset < 1.4.2
pypi/apache-superset 0 - 1.4.2PyPI
Published Apr 13, 2022
Tracked Since Feb 18, 2026