[#FMS-883-99084]: CVE-2021-41972: Apache Superset: Credentials leak

2021-11-11 Thread AARDEX Group
Hello,

Thank you for your interest in AARDEX Group products and services. We are 
processing your inquiry and a member of our staff will review and reply shortly.

If you have any additional information that you think will help us to assist 
you, please feel free to reply to this email.  

AARDEX Team

https://www.aardexgroup.com


Re: [VOTE][SIP-75] Proposal for embeddable dashboards

2021-11-11 Thread Aaron Suddjian
The SIP passes! Voting is now closed, thank you to all participants.

4 binding +1 votes:
Beto, Jiali, Diego, Phillip

2 non-binding +1 votes:
Anu, Srini

On Thu, Nov 4, 2021 at 11:42 AM Phillip Kelley-Dotson 
wrote:

> +1
>
> On Thu, Nov 4, 2021 at 7:35 AM Diego Pucci 
> wrote:
>
> > +1
> >
> > Il giorno mer 3 nov 2021 alle ore 21:03 Anupreet Walia 
> ha
> > scritto:
> >
> > > +1
> > >
> > > > On Nov 3, 2021, at 11:39 AM, Jiali Kuang  wrote:
> > > >
> > > > +1, binding
> > > >
> > > > On Wed, Nov 3, 2021 at 11:38 AM Srinivasa Kadamati 
> > > wrote:
> > > >
> > > >> +1
> > > >>
> > > >> On Wed, Nov 3, 2021 at 2:20 PM Beto Dealmeida
> > > >> 
> > > >> wrote:
> > > >>
> > > >>> +1, binding
> > > >>>
> > > >>> On 11/3/21 11:17 AM, Aaron Suddjian wrote:
> > >  Hi all,
> > > 
> > >  This is a call to vote on SIP-75, a proposal to make dashboards
> > > >>> embeddable
> > >  in third-party applications. More details and discussion can be
> > found
> > > >> on
> > >  GitHub: https://github.com/apache/superset/issues/17187
> > > 
> > >  The vote will be open for at least 1 week or until the necessary
> > > number
> > > >>> of
> > >  votes are reached.
> > > 
> > >  Please vote accordingly:
> > >  [ ] +1 approve
> > >  [ ] +0 no opinion
> > >  [ ] -1 disapprove with the reason
> > > 
> > >  Thank you!
> > > 
> > > >>>
> > > >>>
> > > >>
> > > >
> > > >
> > > > --
> > > > *Lily Kuang*
> > > > Full Stack Engineer
> > > > Preset | https://preset.io
> > >
> > >
> >
>


-- 
Aaron Suddjian, Software Engineer at Preset


CVE-2021-41972: Apache Superset: Credentials leak

2021-11-11 Thread Daniel Gaspar
Description:

Apache Superset up to and including 1.3.1 allowed for database connections 
password leak for authenticated users. This information could be accessed in a 
non-trivial way.


Mitigation:

Upgrade to Apache Superset 1.3.2 or higher

Credit:

Apache Superset team would like to thank Ke Zhu for reporting this issue