Beveiligingsadvies

CVE-2026-23980

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-02-24 12:54:09
Laatst bijgewerkt 2026-02-24 18:19:36
Toegewezen door apache
CVSS-score 5.3
Status PUBLISHED

Beschrijving

Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue.