Skip to content
Apache SupersetGHSA-5cx2-vq3h-x52c

Apache superset missing check for default SECRET_KEY

High8.9CVE-2023-27524 · Published Apr 24, 2023 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 2.1.02.1.0
Details and references

Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L/E:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-1188
Also known as
BIT-superset-2023-27524, CVE-2023-27524, PYSEC-2026-1161

More Apache Superset advisories

All Apache Superset
DateAdvisory
Apr 172023Apache Superset vulnerable to Improper Authorization
CVE-2023-27525Medium4.3no fix yet
Jul 62023Apache Superset Server-Side Request Forgery vulnerability
CVE-2023-25504Medium6.5fixed in 2.1.0
Jul 62023Apache Superset vulnerable to Exposure of Sensitive Information
CVE-2023-30776Medium6.5fixed in 2.1.0
Jan 162023Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints
CVE-2022-43719High8.8no fix yet
Jan 162023Apache Superset is vulnerable to Cross-Site Scripting (XSS)
CVE-2022-43718Medium5.4no fix yet
Jan 162023Apache Superset vulnerable to Cross-site Scripting
CVE-2022-43717Medium5.4no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.