2024-02-28 13:01:09 +00:00
{
"id" : "CVE-2024-24779" ,
"sourceIdentifier" : "security@apache.org" ,
"published" : "2024-02-28T12:15:47.660" ,
2025-02-13 19:04:13 +00:00
"lastModified" : "2025-02-13T18:17:09.103" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2024-02-28 13:01:09 +00:00
"descriptions" : [
{
"lang" : "en" ,
2025-02-13 19:04:13 +00:00
"value" : "Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to unauthorized data.\nThis issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.\n\nUsers are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue."
2024-12-08 03:06:42 +00:00
} ,
{
"lang" : "es" ,
"value" : "Apache Superset con roles personalizados que incluyen \"puede escribir en el conjunto de datos\" y sin todos los permisos de acceso a los datos, permite a los usuarios crear conjuntos de datos virtuales para datos a los que no tienen acceso. Estos usuarios podr\u00edan luego usar esos conjuntos de datos virtuales para obtener acceso a datos no autorizados. Este problema afecta a Apache Superset: antes de la versi\u00f3n 3.0.4, desde la 3.1.0 hasta la 3.1.1. Se recomienda a los usuarios que actualicen a la versi\u00f3n 3.1.1 o 3.0.4, que soluciona el problema."
2024-02-28 13:01:09 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "security@apache.org" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.0 ,
"baseSeverity" : "MEDIUM" ,
2024-02-28 13:01:09 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2024-02-28 13:01:09 +00:00
} ,
"exploitabilityScore" : 3.1 ,
"impactScore" : 1.4
2024-12-31 17:03:44 +00:00
} ,
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" ,
"baseScore" : 6.5 ,
"baseSeverity" : "MEDIUM" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE"
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 3.6
2024-02-28 13:01:09 +00:00
}
]
} ,
"weaknesses" : [
{
"source" : "security@apache.org" ,
2025-03-23 03:03:54 +00:00
"type" : "Primary" ,
2024-02-28 13:01:09 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-863"
}
]
}
] ,
2024-12-31 17:03:44 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "3.0.4" ,
"matchCriteriaId" : "F5D1642C-2CB9-43A0-B816-4E44354F1521"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "3.1.0" ,
"versionEndExcluding" : "3.1.1" ,
"matchCriteriaId" : "FFA07ED1-0A94-4801-8C7B-D38FADC4CEB8"
}
]
}
]
}
] ,
2024-02-28 13:01:09 +00:00
"references" : [
2024-03-07 12:27:24 +00:00
{
"url" : "http://www.openwall.com/lists/oss-security/2024/02/28/6" ,
2024-12-31 17:03:44 +00:00
"source" : "security@apache.org" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
2024-03-07 12:27:24 +00:00
} ,
2024-02-28 13:01:09 +00:00
{
"url" : "https://lists.apache.org/thread/xzhz1m5bb9zxhyqgoy4q2d689b3zp4pq" ,
2024-12-31 17:03:44 +00:00
"source" : "security@apache.org" ,
"tags" : [
"Mailing List" ,
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "http://www.openwall.com/lists/oss-security/2024/02/28/6" ,
2024-12-31 17:03:44 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://lists.apache.org/thread/xzhz1m5bb9zxhyqgoy4q2d689b3zp4pq" ,
2024-12-31 17:03:44 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List" ,
"Vendor Advisory"
]
2024-02-28 13:01:09 +00:00
}
]
}