-
CVSS Score
-The vulnerability stems from improper authorization in import functionality. Based on Superset's architecture:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| apache-superset | pip | <= 3.0.3 | 3.0.4 |
| apache-superset | pip | >= 3.1.0, < 3.1.1 | 3.1.1 |