Users can view database names in Apache Superset
Moderate severity
GitHub Reviewed
Published
Feb 26, 2020
to the GitHub Advisory Database
•
Updated Sep 5, 2024
Description
Published by the National Vulnerability Database
Dec 16, 2019
Reviewed
Feb 25, 2020
Published to the GitHub Advisory Database
Feb 26, 2020
Last updated
Sep 5, 2024
In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab
References