Skip to content
Apache SupersetGHSA-5474-f7g5-273q

Apache Superset: Improper validation of SQL statements allows for unauthorized access to data

Medium4.9CVE-2024-24773 · Published Feb 28, 2024 · updated Jul 7, 2026

Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1, which fixes the issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 3.0.43.0.4
>= 3.1.0, < 3.1.13.1.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
BIT-superset-2024-24773, CVE-2024-24773, PYSEC-2026-1160

More Apache Superset advisories

All Apache Superset
Advisory
Apache Superset Incorrect Authorization vulnerability
Medium4.3May 7, 2024
Apache Superset: Improper authorization validation on dashboards and charts import
Medium4.3Feb 28, 2024
Apache Superset: Improper data authorization when creating a new dataset
Medium5.0Feb 28, 2024
Apache Superset: Improper Neutralization of custom SQL on embedded context
Medium4.3Feb 28, 2024
Apache Superset: Improper error handling on alerts
Medium4.3Feb 28, 2024
Cross-site Scripting in Apache superset
Critical9.6Jan 23, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.