A where_in JINJA macro allows users... CVE-2023-49736

- AV AC AU C I A
发布: 2023-12-19
修订: 2023-12-28

A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Superset.This issue affects Apache Superset: before 2.1.2, from 3.0.0 before 3.0.2. Users are recommended to upgrade to version 3.0.2, which fixes the issue.

0%
暂无可用Exp或PoC
当前有2条受影响产品信息