Apache SupersetGHSA-3hp7-4qq4-v5c6
Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
Medium6.5CVE-2023-42504 · Published Nov 28, 2023 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 3.0.0 | 3.0.0 |
Details and references
An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial of service. This issue affects Apache Superset: before 3.0.0
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-770
- Also known as
- BIT-superset-2023-42504, CVE-2023-42504, PYSEC-2026-1157
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 272023 | Apache Superset has Incorrect Default Permissions CVE-2023-42501Medium4.3fixed in 2.1.2 | Medium4.3 | 2.1.2 |
| Nov 272023 | Apache Superset Cross-site Scripting vulnerability CVE-2023-43701Medium4.3fixed in 2.1.2 | Medium4.3 | 2.1.2 |
| Nov 282023 | Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability CVE-2023-42505Medium4.3fixed in 3.0.0 | Medium4.3 | 3.0.0 |
| Nov 282023 | Apache Superset Open Redirect vulnerability CVE-2023-42502Medium5.4fixed in 3.0.0 | Medium5.4 | 3.0.0 |
| Nov 282023 | Apache Superset - Elevation of Privilege CVE-2023-40610High7.3fixed in 2.1.2 | High7.3 | 2.1.2 |
| Dec 192023 | Apache Superset uncontrolled resource consumption CVE-2023-46104Medium6.5fixed in 2.1.2, 3.1.0rc1 | Medium6.5 | 2.1.2, 3.1.0rc1 |