Apache SupersetGHSA-2cx9-54hp-r698
Apache Superset: Error verbosity exposes metadata in analytics databases
Medium5.3CVE-2024-53948 · Published Dec 9, 2024 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 4.1.0 | 4.1.0 |
Details and references
Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-209
- Also known as
- BIT-superset-2024-53948, CVE-2024-53948, PYSEC-2026-1154
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 92024 | Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled CVE-2024-53949High6.5fixed in 4.1.0 | High6.5 | 4.1.0 |
| Dec 92024 | Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions CVE-2024-53947Low9.8fixed in 4.1.0 | Low9.8 | 4.1.0 |
| Dec 122024 | Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access CVE-2024-55633High6.5fixed in 4.1.0 | High6.5 | 4.1.0 |
| Jul 162024 | Apache Superset vulnerable to improper SQL authorization CVE-2024-39887Medium4.3fixed in 4.0.2 | Medium4.3 | 4.0.2 |
| May 132025 | Apache Superset Allows Ownership Takeover CVE-2025-27696Medium8.8fixed in 4.1.2 | Medium8.8 | 4.1.2 |
| Jun 202024 | Apache Superset server arbitrary file read CVE-2024-34693Medium6.8fixed in 3.1.3, 4.0.1 | Medium6.8 | 3.1.3, 4.0.1 |