WhisperX tag archive

#query-authorization

This page collects WhisperX intelligence signals tagged #query-authorization. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-26 18:54:06 · GitHub Issues

1. Apache Superset CVE-2024-39887: PostgreSQL Blocklist Gap Enables SQL Restriction Bypass

A SQL injection vulnerability in Apache Superset's PostgreSQL query authorization layer could allow attackers to bypass intended security restrictions. Tracked as CVE-2024-39887, the flaw centers on missing functions—particularly query_to_xml—from Superset's DISALLOWED_SQL_FUNCTIONS blocklist, enabling certain dangerou...