CVE-2025-48912
Last modified
CVE-2025-48912 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unauthorized access to data. This issue affects Apache Superset: before 4.1.2. Users are recommended to upgrade to version 4.1.2, which fixes the issue.. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unauthorized access to data. This issue affects Apache Superset: before 4.1.2. Users are recommended to upgrade to version 4.1.2, which fixes the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Superset | < 4.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-48912?
How severe is CVE-2025-48912?
How do I fix CVE-2025-48912?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-48907Deserialization vulnerability in the IPC module Impact: Succ…6.2
- CVE-2025-48908Ability Auto Startup service vulnerability in the foundation…6.7
- CVE-2025-48909Bypass vulnerability in the device management channel Impact…7.1
- CVE-2025-4891A vulnerability was found in code-projects Police Station Ma…7.8
- CVE-2025-48910Buffer overflow vulnerability in the DFile module Impact: Su…5.5
- CVE-2025-48911Vulnerability of improper permission assignment in the note …8.2
- CVE-2025-48913If untrusted users are allowed to configure JMS for Apache C…9.8
- CVE-2025-48914Improper Neutralization of Input During Web Page Generation …8.6
- CVE-2025-48915Improper Neutralization of Input During Web Page Generation …8.6
- CVE-2025-48916Missing Authorization vulnerability in Drupal Bookable Calen…6.5
- CVE-2025-48917Improper Neutralization of Input During Web Page Generation …5
- CVE-2025-48918Improper Neutralization of Input During Web Page Generation …8.8
Are you affected by CVE-2025-48912?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
