<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<!-- MHonArc v2.6.19+ -->
  <channel>
    <title>user</title>
    <link>http://www.mail-archive.com/user@superset.apache.org</link>
    <description>user @ superset.apache</description>
    <pubDate>Tue, 24 Feb 2026 09:46:56 GMT</pubDate>
    <lastBuildDate>Tue, 24 Feb 2026 09:46:56 GMT</lastBuildDate>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <generator>MHonArc RSS 2.0 RCFile</generator>
    <webMaster>themailarchive@gmail.com (The Mail Archive)</webMaster>
    <image>
       <title>The Mail Archive</title>
       <url>http://www.mail-archive.com/nanologo.png</url>
       <link>http://www.mail-archive.com/user@superset.apache.org</link>
    </image>
 
    <item>
      <title>CVE-2026-23984: Apache Superset: SQLLab Read-Only Bypass on PostgreSQL</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00055.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/02/24&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 24 Feb 2026 09:46:55 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00055.html</guid>
   </item>
    <item>
      <title>CVE-2026-23983: Apache Superset: Sensitive Data Exposure via REST API (disabled by default)</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00054.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/02/24&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 24 Feb 2026 09:42:45 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00054.html</guid>
   </item>
    <item>
      <title>CVE-2026-23982: Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00053.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/02/24&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 24 Feb 2026 09:35:50 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00053.html</guid>
   </item>
    <item>
      <title>CVE-2026-23980: Apache Superset: Improper Neutralization of Special Elements used in a SQL Command</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00052.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/02/24&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 24 Feb 2026 09:27:47 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00052.html</guid>
   </item>
    <item>
      <title>CVE-2026-23969: Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00051.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/02/24&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 24 Feb 2026 09:23:07 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00051.html</guid>
   </item>
    <item>
      <title>Consulting request</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00050.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2026/02/13&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Julien Béti%22&quot;&gt;Julien Béti&lt;/a&gt;</description>
      <pubDate>Fri, 13 Feb 2026 16:48:34 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00050.html</guid>
   </item>
    <item>
      <title>Security advisory: Insecure default ClickHouse function list</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00049.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/11/24&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Mon, 24 Nov 2025 10:48:19 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00049.html</guid>
   </item>
    <item>
      <title>Insufficient Session Expiration and Secret Key Management Guidance</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00048.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/11/24&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Mon, 24 Nov 2025 10:12:33 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00048.html</guid>
   </item>
    <item>
      <title>CVE-2025-55675: Apache Superset: Incorrect datasource authorization on REST API</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00047.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/08/14&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Thu, 14 Aug 2025 11:44:43 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00047.html</guid>
   </item>
    <item>
      <title>CVE-2025-55674: Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00046.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/08/14&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Thu, 14 Aug 2025 11:41:37 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00046.html</guid>
   </item>
    <item>
      <title>CVE-2025-55672: Apache Superset: Store XSS on charts metadata</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00045.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/08/14&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Thu, 14 Aug 2025 11:38:24 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00045.html</guid>
   </item>
    <item>
      <title>CVE-2025-55673: Apache Superset: Metadata exposure in embedded charts</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00044.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/08/14&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Thu, 14 Aug 2025 11:34:05 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00044.html</guid>
   </item>
    <item>
      <title>Re: Include Non-metric Columns in Bar Chart Tooltip in Apache Superset</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00043.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/07/14&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Elizabeth Thompson%22&quot;&gt;Elizabeth Thompson&lt;/a&gt;</description>
      <pubDate>Mon, 14 Jul 2025 16:28:40 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00043.html</guid>
   </item>
    <item>
      <title>graph chart with different node icons</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00042.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/06/29&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22u...@moosheimer.com%22&quot;&gt;u...@moosheimer.com&lt;/a&gt;</description>
      <pubDate>Sun, 29 Jun 2025 11:41:11 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00042.html</guid>
   </item>
    <item>
      <title>New Cartodiagram Map</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00041.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/06/29&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22u...@moosheimer.com%22&quot;&gt;u...@moosheimer.com&lt;/a&gt;</description>
      <pubDate>Sun, 29 Jun 2025 11:37:35 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00041.html</guid>
   </item>
    <item>
      <title>CVE-2025-48912: Apache Superset: Improper authorization bypass on row level security via SQL Injection</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00040.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/05/30&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Fri, 30 May 2025 09:36:30 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00040.html</guid>
   </item>
    <item>
      <title>CVE-2025-27696: Apache Superset: Improper authorization leading to resource ownership takeover</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00039.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/05/12&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Mon, 12 May 2025 14:39:56 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00039.html</guid>
   </item>
    <item>
      <title>Downlod data with superset</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00038.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2025/01/20&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Andreas . Moroder%22&quot;&gt;Andreas . Moroder&lt;/a&gt;</description>
      <pubDate>Mon, 20 Jan 2025 07:27:30 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00038.html</guid>
   </item>
    <item>
      <title>Building several charts from a single invocation of a query</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00037.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/07/19&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Anton Shepelev%22&quot;&gt;Anton Shepelev&lt;/a&gt;</description>
      <pubDate>Fri, 19 Jul 2024 15:51:41 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00037.html</guid>
   </item>
    <item>
      <title>CVE-2024-39887: Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00036.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/07/16&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 16 Jul 2024 09:02:41 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00036.html</guid>
   </item>
    <item>
      <title>CVE-2024-34693: Apache Superset: Server arbitrary file read</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00035.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/06/20&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Thu, 20 Jun 2024 08:14:12 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00035.html</guid>
   </item>
    <item>
      <title>CVE-2024-28148: Apache Superset: Incorrect datasource authorization on explore REST API</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00034.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/05/07&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 07 May 2024 08:54:31 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00034.html</guid>
   </item>
    <item>
      <title>Participate in the ASF 25th Anniversary Campaign</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00033.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/04/03&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Brian Proffitt%22&quot;&gt;Brian Proffitt&lt;/a&gt;</description>
      <pubDate>Wed, 03 Apr 2024 13:55:11 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00033.html</guid>
   </item>
    <item>
      <title>Community Over Code NA 2024 Travel Assistance Applications now open!</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00032.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/03/27&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Gavin McDonald%22&quot;&gt;Gavin McDonald&lt;/a&gt;</description>
      <pubDate>Wed, 27 Mar 2024 09:12:28 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00032.html</guid>
   </item>
    <item>
      <title>CVE-2024-25128: Vulnerability in custom, long deprecated OpenID (NOT OIDC) authentication method in Flask AppBuilder</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00031.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/02/28&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Wed, 28 Feb 2024 14:08:16 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00031.html</guid>
   </item>
    <item>
      <title>CVE-2024-26016: Apache Superset: Improper authorization validation on dashboards and charts import</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00030.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/02/28&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Wed, 28 Feb 2024 10:44:12 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00030.html</guid>
   </item>
    <item>
      <title>CVE-2024-24779: Apache Superset: Improper data authorization when creating a new dataset</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00029.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/02/28&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Wed, 28 Feb 2024 10:34:26 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00029.html</guid>
   </item>
    <item>
      <title>CVE-2024-24772: Apache Superset: Improper Neutralisation of custom SQL on embedded context</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00028.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/02/28&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Wed, 28 Feb 2024 10:26:05 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00028.html</guid>
   </item>
    <item>
      <title>CVE-2024-24773: Apache Superset: Improper validation of SQL statements allows for unauthorized access to data</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00027.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/02/28&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Wed, 28 Feb 2024 10:12:58 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00027.html</guid>
   </item>
    <item>
      <title>CVE-2024-27315: Apache Superset: Improper error handling on alerts</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00026.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/02/28&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Wed, 28 Feb 2024 10:00:36 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00026.html</guid>
   </item>
    <item>
      <title>Community Over Code Asia 2024 Travel Assistance Applications now open!</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00025.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/02/20&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Gavin McDonald%22&quot;&gt;Gavin McDonald&lt;/a&gt;</description>
      <pubDate>Tue, 20 Feb 2024 09:24:32 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00025.html</guid>
   </item>
    <item>
      <title>CVE-2024-23952: Apache Superset: Allows for uncontrolled resource consumption via a ZIP bomb (version range fix for CVE-2023-46104)</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00024.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/02/14&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Wed, 14 Feb 2024 11:03:12 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00024.html</guid>
   </item>
    <item>
      <title>Community over Code EU 2024 Travel Assistance Applications now open!</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00023.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/02/03&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Gavin McDonald%22&quot;&gt;Gavin McDonald&lt;/a&gt;</description>
      <pubDate>Sat, 03 Feb 2024 08:49:44 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00023.html</guid>
   </item>
    <item>
      <title>[no subject]</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00022.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/02/03&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Gavin McDonald%22&quot;&gt;Gavin McDonald&lt;/a&gt;</description>
      <pubDate>Sat, 03 Feb 2024 08:29:46 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00022.html</guid>
   </item>
    <item>
      <title>Security advisory: session logout expiration</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00021.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/01/23&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 23 Jan 2024 13:42:41 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00021.html</guid>
   </item>
    <item>
      <title>CVE-2023-49657: Apache Superset: Stored XSS in Dashboard Title and Chart Title</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00020.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/01/23&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 23 Jan 2024 13:18:17 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00020.html</guid>
   </item>
    <item>
      <title>Security advisory: default SECRET_KEY in Helm Chart</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00019.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2024/01/19&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22dpgas...@apache.org%22&quot;&gt;dpgas...@apache.org&lt;/a&gt;</description>
      <pubDate>Fri, 19 Jan 2024 12:44:36 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00019.html</guid>
   </item>
    <item>
      <title>CVE-2023-49734: Apache Superset: Privilege Escalation Vulnerability</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00018.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/12/19&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 19 Dec 2023 09:44:07 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00018.html</guid>
   </item>
    <item>
      <title>CVE-2023-49736: Apache Superset: SQL Injection on where_in JINJA macro</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00017.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/12/19&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 19 Dec 2023 09:31:21 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00017.html</guid>
   </item>
    <item>
      <title>CVE-2023-46104: Apache Superset: Allows for uncontrolled resource consumption via a ZIP bomb</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00016.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/12/19&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 19 Dec 2023 09:14:16 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00016.html</guid>
   </item>
    <item>
      <title>CVE-2023-42504: Apache Superset: Lack of rate limiting allows for possible denial of service</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00015.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/11/28&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 28 Nov 2023 16:39:31 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00015.html</guid>
   </item>
    <item>
      <title>CVE-2023-42505: Apache Superset: Sensitive information disclosure on db connection details</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00014.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/11/28&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 28 Nov 2023 16:20:21 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00014.html</guid>
   </item>
    <item>
      <title>CVE-2023-42502: Apache Superset: Open Redirect Vulnerability</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00013.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/11/28&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Tue, 28 Nov 2023 16:09:00 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00013.html</guid>
   </item>
    <item>
      <title>CVE-2023-43701: Apache Superset: Stored XSS on API endpoint</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00012.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/11/27&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Mon, 27 Nov 2023 09:44:37 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00012.html</guid>
   </item>
    <item>
      <title>CVE-2023-42501: Apache Superset: Unnecessary read permissions within the Gamma role</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00011.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/11/27&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Mon, 27 Nov 2023 09:40:15 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00011.html</guid>
   </item>
    <item>
      <title>CVE-2023-40610: Apache Superset: Privilege escalation with default examples database</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00010.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/11/27&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Mon, 27 Nov 2023 09:31:09 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00010.html</guid>
   </item>
    <item>
      <title>Cross Filter and Area Chart</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00009.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/11/26&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22u...@moosheimer.com%22&quot;&gt;u...@moosheimer.com&lt;/a&gt;</description>
      <pubDate>Sun, 26 Nov 2023 13:12:46 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00009.html</guid>
   </item>
    <item>
      <title>CVE-2023-32672: Apache Superset: SQL parser edge case bypasses data access authorization</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00008.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/09/06&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Wed, 06 Sep 2023 09:46:14 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00008.html</guid>
   </item>
    <item>
      <title>CVE-2023-37941: Apache Superset: Metadata db write access can lead to remote code execution</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00007.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/09/06&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Wed, 06 Sep 2023 09:41:02 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00007.html</guid>
   </item>
    <item>
      <title>CVE-2023-39265: Apache Superset: Possible Unauthorized Registration of SQLite Database Connections</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00006.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/09/06&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Wed, 06 Sep 2023 09:34:46 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00006.html</guid>
   </item>
    <item>
      <title>CVE-2023-39264: Apache Superset: Stack traces enabled by default</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00005.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/09/06&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Wed, 06 Sep 2023 09:26:43 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00005.html</guid>
   </item>
    <item>
      <title>CVE-2023-36388: Apache Superset: Improper API permission for low privilege users allows for SSRF</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00004.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/09/06&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Wed, 06 Sep 2023 09:11:08 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00004.html</guid>
   </item>
    <item>
      <title>CVE-2023-36387: Apache Superset: Improper API permission for low privilege users</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00003.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/09/06&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Daniel Gaspar%22&quot;&gt;Daniel Gaspar&lt;/a&gt;</description>
      <pubDate>Wed, 06 Sep 2023 09:06:36 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00003.html</guid>
   </item>
    <item>
      <title>Registration open for Community Over Code North America</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00002.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/08/28&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Rich Bowen%22&quot;&gt;Rich Bowen&lt;/a&gt;</description>
      <pubDate>Mon, 28 Aug 2023 19:43:09 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00002.html</guid>
   </item>
    <item>
      <title>TAC Applications for Community Over Code North America and Asia now open</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00001.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/06/16&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Gavin McDonald%22&quot;&gt;Gavin McDonald&lt;/a&gt;</description>
      <pubDate>Fri, 16 Jun 2023 08:55:23 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00001.html</guid>
   </item>
    <item>
      <title>Apache Superset Vulnerability: Insecure Default Configuration Exposes Servers to RCE Attacks</title>
      <link>http://www.mail-archive.com/user@superset.apache.org/msg00000.html</link>
      <description>&lt;font color=#6f6f6f&gt; 2023/04/26&lt;/font&gt; -- &lt;a href=&quot;http://www.mail-archive.com/search?l=user@superset.apache.org&amp;q=from:%22Turritopsis Dohrnii Teo En Ming%22&quot;&gt;Turritopsis Dohrnii Teo En Ming&lt;/a&gt;</description>
      <pubDate>Wed, 26 Apr 2023 13:46:00 GMT</pubDate>
      <guid isPermaLink="true">http://www.mail-archive.com/user@superset.apache.org/msg00000.html</guid>
   </item>
 
  </channel>
  </rss>
<!-- MHonArc v2.6.19+ -->
