Apache SupersetGHSA-7jhg-8m74-6f6g
Apache Superset vulnerable to Improper Authorization
Medium4.3CVE-2023-27525 · Published Apr 17, 2023 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | <= 2.0.1 | No fix yet |
Details and references
An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-863
- Also known as
- BIT-superset-2023-27525, CVE-2023-27525, PYSEC-2026-1163
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 242023 | Apache superset missing check for default SECRET_KEY CVE-2023-27524High8.9fixed in 2.1.0 | High8.9 | 2.1.0 |
| Jul 62023 | Apache Superset Server-Side Request Forgery vulnerability CVE-2023-25504Medium6.5fixed in 2.1.0 | Medium6.5 | 2.1.0 |
| Jul 62023 | Apache Superset vulnerable to Exposure of Sensitive Information CVE-2023-30776Medium6.5fixed in 2.1.0 | Medium6.5 | 2.1.0 |
| Jan 162023 | Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints CVE-2022-43719High8.8no fix yet | High8.8 | No fix yet |
| Jan 162023 | Apache Superset is vulnerable to Cross-Site Scripting (XSS) CVE-2022-43718Medium5.4no fix yet | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset vulnerable to Cross-site Scripting CVE-2022-43717Medium5.4no fix yet | Medium5.4 | No fix yet |