Apache SupersetGHSA-5cx2-vq3h-x52c
Apache superset missing check for default SECRET_KEY
High8.9CVE-2023-27524 · Published Apr 24, 2023 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 2.1.0 | 2.1.0 |
Details and references
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L/E:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-1188
- Also known as
- BIT-superset-2023-27524, CVE-2023-27524, PYSEC-2026-1161
- nvd.nist.gov/vuln/detail/CVE-2023-27524
- github.com/apache/superset/commit/b180319bbf08e876ea84963220ebebbfd0699e03
- github.com/apache/superset
- lists.apache.org/thread/n0ftx60sllf527j7g11kmt24wvof8xyk
- packetstormsecurity.com/files/172522/Apache-Superset-2.0.0-Authentication-Bypass.html
- packetstormsecurity.com/files/175094/Apache-Superset-2.0.0-Remote-Code-Execution.html
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27524
- www.openwall.com/lists/oss-security/2023/04/24/2
- www.openwall.com/lists/oss-security/2023/04/24/2
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 172023 | Apache Superset vulnerable to Improper Authorization CVE-2023-27525Medium4.3no fix yet | Medium4.3 | No fix yet |
| Jul 62023 | Apache Superset Server-Side Request Forgery vulnerability CVE-2023-25504Medium6.5fixed in 2.1.0 | Medium6.5 | 2.1.0 |
| Jul 62023 | Apache Superset vulnerable to Exposure of Sensitive Information CVE-2023-30776Medium6.5fixed in 2.1.0 | Medium6.5 | 2.1.0 |
| Jan 162023 | Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints CVE-2022-43719High8.8no fix yet | High8.8 | No fix yet |
| Jan 162023 | Apache Superset is vulnerable to Cross-Site Scripting (XSS) CVE-2022-43718Medium5.4no fix yet | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset vulnerable to Cross-site Scripting CVE-2022-43717Medium5.4no fix yet | Medium5.4 | No fix yet |