Apache SupersetGHSA-9832-mgg4-3gr6
Apache Superset has improper default REST API permission for Gamma users
Medium5.4CVE-2023-36387 · Published Sep 6, 2023 · updated Jul 7, 2026
An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | <= 2.1.0 | No fix yet |
Details and references
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 62023 | Apache Superset has incorrect authorization check | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset Deserialization of Untrusted Data vulnerability | Medium6.6 | 2.1.1 |
| Sep 62023 | Apache Superset Improper Input Validation vulnerability | Medium6.5 | No fix yet |
| Sep 62023 | Apache Superset Server Side Request Forgery vulnerability | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset users may incorrectly create resources using the import charts feature | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset may expose internal traces on REST API endpoints | Medium4.3 | No fix yet |