Skip to content
Apache SupersetGHSA-299q-3p96-5898

Apache Superset Incorrect Authorization vulnerability

Medium4.3CVE-2024-28148 · Published May 7, 2024 · updated Jul 7, 2026

An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request. This issue affects Apache Superset before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 3.1.23.1.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
BIT-superset-2024-28148, CVE-2024-28148, PYSEC-2026-1153

More Apache Superset advisories

All Apache Superset
Advisory
Apache Superset server arbitrary file read
Medium6.8Jun 20, 2024
Apache Superset: Improper authorization validation on dashboards and charts import
Medium4.3Feb 28, 2024
Apache Superset: Improper data authorization when creating a new dataset
Medium5.0Feb 28, 2024
Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
Medium4.9Feb 28, 2024
Apache Superset: Improper Neutralization of custom SQL on embedded context
Medium4.3Feb 28, 2024
Apache Superset: Improper error handling on alerts
Medium4.3Feb 28, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.