Skip to content
Apache SupersetGHSA-4fg9-5w46-xmrj

Apache Superset Server Side Request Forgery vulnerability

Medium4.3CVE-2023-36388 · Published Sep 6, 2023 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
<= 2.1.0No fix yet
Details and references

Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possible SSRF.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-918
Also known as
BIT-superset-2023-36388, CVE-2023-36388, PYSEC-2026-1159

More Apache Superset advisories

All Apache Superset
DateAdvisory
Sep 62023Apache Superset has improper default REST API permission for Gamma users
CVE-2023-36387Medium5.4no fix yet
Sep 62023Apache Superset users may incorrectly create resources using the import charts feature
CVE-2023-27526Medium4.3no fix yet
Sep 62023Apache Superset may expose internal traces on REST API endpoints
CVE-2023-39264Medium4.3no fix yet
Sep 62023Apache Superset vulnerable to improper data authorization
CVE-2023-27523Medium5.0no fix yet
Sep 62023Apache Superset has incorrect authorization check
CVE-2023-32672Medium4.3no fix yet
Sep 62023Apache Superset Deserialization of Untrusted Data vulnerability
CVE-2023-37941Medium6.6fixed in 2.1.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.