Skip to content
Apache SupersetGHSA-95ch-p3gw-23qg

Apache Superset has incorrect authorization check

Medium4.3CVE-2023-32672 · Published Sep 6, 2023 · updated Jul 7, 2026

An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability can be exploited by leveraging a SQL parsing vulnerability.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
<= 2.1.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
BIT-superset-2023-32672, CVE-2023-32672, PYSEC-2026-1166

More Apache Superset advisories

All Apache Superset
Advisory
Apache Superset Deserialization of Untrusted Data vulnerability
Medium6.6Sep 6, 2023
Apache Superset Improper Input Validation vulnerability
Medium6.5Sep 6, 2023
Apache Superset Server Side Request Forgery vulnerability
Medium4.3Sep 6, 2023
Apache Superset has improper default REST API permission for Gamma users
Medium5.4Sep 6, 2023
Apache Superset users may incorrectly create resources using the import charts feature
Medium4.3Sep 6, 2023
Apache Superset may expose internal traces on REST API endpoints
Medium4.3Sep 6, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.