Vulnerabilities > Apache > Superset > 1.3.2

DATE CVE VULNERABILITY TITLE RISK
2022-04-13 CVE-2022-27479 SQL Injection vulnerability in Apache Superset
Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests.
network
low complexity
apache CWE-89
critical
9.8
2022-02-01 CVE-2021-44451 Insufficiently Protected Credentials vulnerability in Apache Superset
Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users.
network
low complexity
apache CWE-522
6.5
2021-11-17 CVE-2021-42250 Improper Encoding or Escaping of Output vulnerability in Apache Superset
Improper output neutralization for Logs.
network
low complexity
apache CWE-116
6.5