Skip to content
Apache SupersetGHSA-8f5j-mgx9-5hm5

Apache Superset has Improper Access Control

Medium5.3CVE-2022-45438 · Published Jan 16, 2023 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
<= 1.5.2No fix yet
<= 2.0.0No fix yet
Details and references

When explicitly enabling the feature flag `DASHBOARD_CACHE` (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-284, CWE-668
Also known as
BIT-superset-2022-45438, CVE-2022-45438, PYSEC-2026-778

More Apache Superset advisories

All Apache Superset
DateAdvisory
Jan 162023Apache Superset Open Redirect vulnerability
CVE-2022-43721Medium5.4no fix yet
Jan 162023Apache Superset vulnerable to Injection
CVE-2022-43720Medium5.4no fix yet
Jan 162023Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints
CVE-2022-43719High8.8no fix yet
Jan 162023Apache Superset is vulnerable to Cross-Site Scripting (XSS)
CVE-2022-43718Medium5.4no fix yet
Jan 162023Apache Superset vulnerable to Cross-site Scripting
CVE-2022-43717Medium5.4no fix yet
Jan 162023Apache Superset's SQL Alchemy connector vulnerable to SQL Injection
CVE-2022-41703Medium5.4no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.