Apache SupersetGHSA-95mg-jgfx-54v9
Apache Superset uncontrolled resource consumption
Medium6.5CVE-2023-46104 · Published Dec 19, 2023 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 2.1.2 | 2.1.2 |
| >= 3.0.0, < 3.1.0rc1 | 3.1.0rc1 |
Details and references
Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets. This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
- Also known as
- BIT-superset-2023-46104, CVE-2023-46104, PYSEC-2026-1167
- nvd.nist.gov/vuln/detail/CVE-2023-46104
- github.com/apache/superset/commit/7c23cb0b3fd224c320b35f05e74b572033569154
- github.com/apache/superset/commit/f473d13d0d89de5990209ff81b17dfe2cee884d3
- github.com/apache/superset
- lists.apache.org/thread/yxbxg4wryb7cb7wyybk11l5nqy0rsrvl
- www.openwall.com/lists/oss-security/2023/12/19/1
- www.openwall.com/lists/oss-security/2024/02/14/2
- www.openwall.com/lists/oss-security/2024/02/14/3
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 192023 | Apache Superset incorrect write permissions vulnerability CVE-2023-49734High7.7fixed in 2.1.3, 3.0.2 | High7.7 | 2.1.3, 3.0.2 |
| Dec 192023 | Apache Superset SQL injection vulnerability CVE-2023-49736Medium6.5fixed in 2.1.3, 3.0.2 | Medium6.5 | 2.1.3, 3.0.2 |
| Nov 282023 | Apache Superset - Elevation of Privilege CVE-2023-40610High7.3fixed in 2.1.2 | High7.3 | 2.1.2 |
| Nov 282023 | Apache Superset Allocation of Resources Without Limits or Throttling vulnerability CVE-2023-42504Medium6.5fixed in 3.0.0 | Medium6.5 | 3.0.0 |
| Nov 282023 | Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability CVE-2023-42505Medium4.3fixed in 3.0.0 | Medium4.3 | 3.0.0 |
| Nov 282023 | Apache Superset Open Redirect vulnerability CVE-2023-42502Medium5.4fixed in 3.0.0 | Medium5.4 | 3.0.0 |