CVE-2025-55673

When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, to the low-privileged guest user. This issue affects Apache Superset: before 4.1.3. Users are recommended to upgrade to version 4.1.3, which fixes the issue.
References
Link Resource
https://lists.apache.org/thread/h2hw756wk4sj4z49blvzkr5fntl9hlf8 Mailing List Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*

History

18 Aug 2025, 18:27

Type Values Removed Values Added
First Time Apache superset
Apache
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
Summary
  • (es) Cuando un usuario invitado accede a un gráfico en Apache Superset, la respuesta de la API del endpoint /chart/data incluye un campo de consulta en su payload. Este campo contiene la consulta subyacente, que revela incorrectamente información del esquema de la base de datos, como los nombres de las tablas, al usuario invitado con pocos privilegios. Este problema afecta a Apache Superset: versiones anteriores a la 4.1.3. Se recomienda actualizar a la versión 4.1.3, que soluciona el problema.
References () https://lists.apache.org/thread/h2hw756wk4sj4z49blvzkr5fntl9hlf8 - () https://lists.apache.org/thread/h2hw756wk4sj4z49blvzkr5fntl9hlf8 - Mailing List, Vendor Advisory
CPE cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*

14 Aug 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-14 14:15

Updated : 2025-08-18 18:27


NVD link : CVE-2025-55673

Mitre link : CVE-2025-55673

CVE.ORG link : CVE-2025-55673


JSON object : View

Products Affected

apache

  • superset
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo