Skip to content
Apache SupersetGHSA-3hp7-4qq4-v5c6

Apache Superset Allocation of Resources Without Limits or Throttling vulnerability

Medium6.5CVE-2023-42504 · Published Nov 28, 2023 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 3.0.03.0.0
Details and references

An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial of service. This issue affects Apache Superset: before 3.0.0

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-770
Also known as
BIT-superset-2023-42504, CVE-2023-42504, PYSEC-2026-1157

More Apache Superset advisories

All Apache Superset
DateAdvisory
Nov 272023Apache Superset has Incorrect Default Permissions
CVE-2023-42501Medium4.3fixed in 2.1.2
Nov 272023Apache Superset Cross-site Scripting vulnerability
CVE-2023-43701Medium4.3fixed in 2.1.2
Nov 282023Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-42505Medium4.3fixed in 3.0.0
Nov 282023Apache Superset Open Redirect vulnerability
CVE-2023-42502Medium5.4fixed in 3.0.0
Nov 282023Apache Superset - Elevation of Privilege
CVE-2023-40610High7.3fixed in 2.1.2
Dec 192023Apache Superset uncontrolled resource consumption
CVE-2023-46104Medium6.5fixed in 2.1.2, 3.1.0rc1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.