CVE-2023-27523

Improper data authorization check on Jinja templated queries in Apache Supersetup to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
apacheCNA
5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVEADP
---
---
CISA-ADPADP
---
---