Skip to content
Apache SupersetGHSA-7jhg-8m74-6f6g

Apache Superset vulnerable to Improper Authorization

Medium4.3CVE-2023-27525 · Published Apr 17, 2023 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
<= 2.0.1No fix yet
Details and references

An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
BIT-superset-2023-27525, CVE-2023-27525, PYSEC-2026-1163

More Apache Superset advisories

All Apache Superset
DateAdvisory
Apr 242023Apache superset missing check for default SECRET_KEY
CVE-2023-27524High8.9fixed in 2.1.0
Jul 62023Apache Superset Server-Side Request Forgery vulnerability
CVE-2023-25504Medium6.5fixed in 2.1.0
Jul 62023Apache Superset vulnerable to Exposure of Sensitive Information
CVE-2023-30776Medium6.5fixed in 2.1.0
Jan 162023Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints
CVE-2022-43719High8.8no fix yet
Jan 162023Apache Superset is vulnerable to Cross-Site Scripting (XSS)
CVE-2022-43718Medium5.4no fix yet
Jan 162023Apache Superset vulnerable to Cross-site Scripting
CVE-2022-43717Medium5.4no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.