WhisperX tag archive

#improper authorization

This page collects WhisperX intelligence signals tagged #improper authorization. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-30 17:54:11 · GitHub Issues

1. Apache Superset SQLLab Flaw Bypasses Read-Only Validation on Postgres Databases

A critical improper authorization vulnerability in Apache Superset's SQLLab enables authenticated users to execute unauthorized write operations on Postgres analytic databases. Attackers with SQLLab access can craft specially designed SQL DML statements that the system incorrectly classifies as read-only queries, effec...

The Lab · 2026-04-30 18:54:14 · GitHub Issues

2. Apache Superset SQLLab Flaw Bypasses Read-Only Query Validation on Postgres Databases

A critical Improper Authorization vulnerability in Apache Superset's SQLLab feature allows authenticated users to execute write operations on Postgres analytic databases that should be restricted to read-only access. The flaw stems from improper validation of SQL DML statements, enabling specially crafted queries to by...