CVE-2022-27479

CRITICAL9.8EPSS 4.3%

SQL injection vulnerability in chart data API

Published: 4/14/2022Modified: 5/20/2025

Description

Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (7)