CVE Published: 18/10/2021 |
CVE Updated: 04/08/2024 |
CVE Year: 2021 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Superset Status : PUBLISHED
CVE-2021-41971 Description
Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malicious authenticated user sends an http request with a custom URL.
CWE-ID: CWE-89 CWE Name: CWE-89 Improper Neutralization of Special Elements used in an SQL Command (
SQL Injection
) Source: Apache Software Foundation
Common Attack Pattern Enumeration and Classification (CAPEC)