CVE-2024-39887

An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorization. To mitigate this, a new configuration key named DISALLOWED_SQL_FUNCTIONS has been introduced. This key disallows the use of the following PostgreSQL functions: version, query_to_xml, inet_server_addr, and inet_client_addr. Additional functions can be added to this list for increased protection. This issue affects Apache Superset: before 4.0.2. Users are recommended to upgrade to version 4.0.2, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*

History

13 Feb 2025, 18:18

Type Values Removed Values Added
Summary (en) An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorization. To mitigate this, a new configuration key named DISALLOWED_SQL_FUNCTIONS has been introduced. This key disallows the use of the following PostgreSQL functions: version, query_to_xml, inet_server_addr, and inet_client_addr. Additional functions can be added to this list for increased protection. This issue affects Apache Superset: before 4.0.2. Users are recommended to upgrade to version 4.0.2, which fixes the issue. (en) An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorization. To mitigate this, a new configuration key named DISALLOWED_SQL_FUNCTIONS has been introduced. This key disallows the use of the following PostgreSQL functions: version, query_to_xml, inet_server_addr, and inet_client_addr. Additional functions can be added to this list for increased protection. This issue affects Apache Superset: before 4.0.2. Users are recommended to upgrade to version 4.0.2, which fixes the issue.

10 Feb 2025, 16:07

Type Values Removed Values Added
CPE cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*
First Time Apache superset
Apache
References () http://www.openwall.com/lists/oss-security/2024/07/16/5 - () http://www.openwall.com/lists/oss-security/2024/07/16/5 - Mailing List, Third Party Advisory
References () https://lists.apache.org/thread/j55vm41jg3l0x6w49zrmvbf3k0ts5fqz - () https://lists.apache.org/thread/j55vm41jg3l0x6w49zrmvbf3k0ts5fqz - Mailing List, Vendor Advisory

Information

Published : 2024-07-16 10:15

Updated : 2025-02-13 18:18


NVD link : CVE-2024-39887

Mitre link : CVE-2024-39887

CVE.ORG link : CVE-2024-39887


JSON object : View

Products Affected

apache

  • superset
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')