Skip to content
Apache SupersetGHSA-cmjc-52fg-9f7j

Apache Superset vulnerable to Exposure of Sensitive Information

Medium6.5CVE-2023-30776 · Published Jul 6, 2023 · updated Jul 7, 2026

An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
>= 1.3.0, < 2.1.02.1.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200
Also known as
BIT-superset-2023-30776, CVE-2023-30776, PYSEC-2026-1171

More Apache Superset advisories

All Apache Superset
Advisory
Apache Superset vulnerable to improper data authorization
Medium5.0Sep 6, 2023
Apache Superset may expose internal traces on REST API endpoints
Medium4.3Sep 6, 2023
Apache Superset users may incorrectly create resources using the import charts feature
Medium4.3Sep 6, 2023
Apache Superset has improper default REST API permission for Gamma users
Medium5.4Sep 6, 2023
Apache Superset Server Side Request Forgery vulnerability
Medium4.3Sep 6, 2023
Apache Superset Server-Side Request Forgery vulnerability
Medium6.5Jul 6, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.