Apache SupersetGHSA-787v-v9vq-4rgv
Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
High6.5CVE-2024-55633 · Published Dec 12, 2024 · updated Jul 7, 2026
Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query, enabling its execution. Non postgres analytics database connections and postgres analytics database connections set with a readonly user (advised) are not vulnerable. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 4.1.0 | 4.1.0 |
Details and references
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 302025 | Apache Superset: Improper authorization bypass on row level security via SQL Injection | High | 4.1.2 |
| May 132025 | Apache Superset Allows Ownership Takeover | Medium8.8 | 4.1.2 |
| Dec 92024 | Apache Superset: Error verbosity exposes metadata in analytics databases | Medium5.3 | 4.1.0 |
| Dec 92024 | Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled | High6.5 | 4.1.0 |
| Dec 92024 | Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions | Low9.8 | 4.1.0 |
| Jul 162024 | Apache Superset vulnerable to improper SQL authorization | Medium4.3 | 4.0.2 |