Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malicious authenticated user sends an http request with a custom URL.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| apache-superset(PyPI) | 0 | 1.3.1 | N/A |
CVSS Metrics