An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unauthorized access to data. This issue affects Apache Superset: before 4.1.2. Users are recommended to upgrade to version 4.1.2, which fixes the issue.
History

Wed, 04 Jun 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache superset
CPEs cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache superset
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Sat, 31 May 2025 01:30:00 +0000

Type Values Removed Values Added
References

Fri, 30 May 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 May 2025 08:45:00 +0000

Type Values Removed Values Added
Description An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unauthorized access to data. This issue affects Apache Superset: before 4.1.2. Users are recommended to upgrade to version 4.1.2, which fixes the issue.
Title Apache Superset: Improper authorization bypass on row level security via SQL Injection
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-05-30T08:26:15.500Z

Updated: 2025-05-31T00:11:45.502Z

Reserved: 2025-05-28T09:28:35.760Z

Link: CVE-2025-48912

cve-icon Vulnrichment

Updated: 2025-05-30T12:55:57.381Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-30T09:15:25.050

Modified: 2025-06-04T18:29:44.323

Link: CVE-2025-48912

cve-icon Redhat

No data.