WhisperX tag archive

#apache-superset

This page collects WhisperX intelligence signals tagged #apache-superset. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (6)

The Lab · 2026-04-26 21:54:09 · GitHub Issues

1. Apache Superset API Access Control Gap Raises Data Exposure Risk, Researchers Warn

Security researchers have identified a broken access control vulnerability in Apache Superset, the widely deployed open-source business intelligence platform. The flaw, classified under OWASP A01:2021, stems from API endpoints missing required @has_access permission decorators, potentially allowing unauthorized users t...

The Lab · 2026-04-27 01:54:06 · GitHub Issues

2. Apache Superset SQL Injection Risk: Critical PostgreSQL Functions Missing from Security Blocklist

A reported vulnerability in Apache Superset reveals that several dangerous PostgreSQL functions capable of data exfiltration and side effects are absent from the application's DISALLOWED_SQL_FUNCTIONS blocklist. The flaw, classified under OWASP A03:2021 — Injection (CWE-89), could allow attackers to bypass intended que...

The Lab · 2026-04-30 01:54:09 · GitHub Issues

3. Authorization Flaw in Apache Superset Allows Low-Privilege Users to Create Roles via Security API

A critical improper authorization vulnerability has been identified in Apache Superset, the open-source data visualization platform. The flaw, which resides in the framework's FAB_ADD_SECURITY_API functionality, permits users with lower privilege levels to interact with administrative role-creation endpoints that shoul...

The Lab · 2026-04-30 02:54:06 · GitHub Issues

4. Apache Superset Improper Authorization Flaw Grants Lower-Privilege Users Access to Role Creation API

A critical improper authorization vulnerability has been identified in Apache Superset when the FAB_ADD_SECURITY_API configuration is enabled, allowing lower-privilege users to create roles through the API. The security flaw, tracked as a significant access control failure, affects versions from 2.0.0 up to but not inc...

The Lab · 2026-04-30 08:54:13 · GitHub Issues

5. Apache Superset SQLLab Flaw Bypasses Read-Only Validation, Exposing Postgres Databases to Unauthorized Writes

A critical authorization weakness in Apache Superset enables users with SQLLab access to bypass read-only query safeguards on Postgres analytic databases. The vulnerability stems from improper validation logic that misidentifies specially crafted SQL DML statements as read-only operations, permitting their execution ag...

The Lab · 2026-04-30 17:54:09 · GitHub Issues

6. Apache Superset Flaw Enables Authenticated Attackers to Read Arbitrary Server Files via MariaDB

A critical input validation vulnerability in Apache Superset exposes affected installations to arbitrary file read attacks by authenticated users through specially crafted MariaDB connections. The flaw leverages the LOCAL_INFILE capability—a database feature disabled by default on MariaDB servers but potentially exploi...