Apache SupersetGHSA-95ch-p3gw-23qg
Apache Superset has incorrect authorization check
Medium4.3CVE-2023-32672 · Published Sep 6, 2023 · updated Jul 7, 2026
An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability can be exploited by leveraging a SQL parsing vulnerability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | <= 2.1.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-863
- Also known as
- BIT-superset-2023-32672, CVE-2023-32672, PYSEC-2026-1166
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 62023 | Apache Superset Deserialization of Untrusted Data vulnerability | Medium6.6 | 2.1.1 |
| Sep 62023 | Apache Superset Improper Input Validation vulnerability | Medium6.5 | No fix yet |
| Sep 62023 | Apache Superset Server Side Request Forgery vulnerability | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset has improper default REST API permission for Gamma users | Medium5.4 | No fix yet |
| Sep 62023 | Apache Superset users may incorrectly create resources using the import charts feature | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset may expose internal traces on REST API endpoints | Medium4.3 | No fix yet |