CVE-2019-12413: Apache Superset
Medium severity, CVSS 5.3. EPSS: 2.8% chance of exploitation in the next 30 days.
In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query.
Affected products
- Apache Superset: before 0.31 (fixed in 0.31)
Published 2019-12-16. Last modified 2026-06-17.