Skip to content
Apache SupersetGHSA-9832-mgg4-3gr6

Apache Superset has improper default REST API permission for Gamma users

Medium5.4CVE-2023-36387 · Published Sep 6, 2023 · updated Jul 7, 2026

An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
<= 2.1.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-281, CWE-863, CWE-918
Also known as
BIT-superset-2023-36387, CVE-2023-36387, PYSEC-2026-1168

More Apache Superset advisories

All Apache Superset
Advisory
Apache Superset has incorrect authorization check
Medium4.3Sep 6, 2023
Apache Superset Deserialization of Untrusted Data vulnerability
Medium6.6Sep 6, 2023
Apache Superset Improper Input Validation vulnerability
Medium6.5Sep 6, 2023
Apache Superset Server Side Request Forgery vulnerability
Medium4.3Sep 6, 2023
Apache Superset users may incorrectly create resources using the import charts feature
Medium4.3Sep 6, 2023
Apache Superset may expose internal traces on REST API endpoints
Medium4.3Sep 6, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.