Apache SupersetGHSA-748r-5r8q-273m
Apache Superset allows authenticated users to access metadata they have no permission to
Medium4.3CVE-2021-37839 · Published Jul 7, 2022 · updated Jul 7, 2026
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 1.5.1 | 1.5.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-273
- Also known as
- BIT-superset-2021-37839, CVE-2021-37839, PYSEC-2026-776
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 242022 | Apache Superset Stored XSS on Dashboard markdown | Medium5.4 | 0.38.1 |
| May 242022 | Apache Superset OS Command Injection | High8.8 | 0.37.1 |
| May 242022 | Improper Encoding or Escaping of Output in Apache Superset | High6.5 | 1.3.2 |
| May 242022 | Apache Superset allowed for database connections password leak for authenticated users | High6.5 | 1.3.2 |
| May 242022 | Apache Superset Cross-site Scripting (XSS) vulnerability on the Explore page | Medium5.4 | 1.2.0 |
| May 242022 | Apache Superset SQL Injection when template processing is enabled | High8.8 | 1.3.1 |