Skip to main content

Improper Check for Dropped Privileges

CVE-2021-37839

Severity Medium
Score 4.3/10

Summary

Apache Superset prior to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • LOW
  • NONE

CWE-273 - Improper Check for Dropped Privileges

The software attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.

Advisory Timeline

  • Published