Apache SupersetGHSA-cpvx-2365-466c
Apache Superset may expose internal traces on REST API endpoints
Medium4.3CVE-2023-39264 · Published Sep 6, 2023 · updated Jul 7, 2026
By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoints to users. This vulnerability exists in Apache Superset versions up to and including 2.1.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | <= 2.1.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-209
- Also known as
- BIT-superset-2023-39264, CVE-2023-39264, PYSEC-2026-1172
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 62023 | Apache Superset has incorrect authorization check | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset Deserialization of Untrusted Data vulnerability | Medium6.6 | 2.1.1 |
| Sep 62023 | Apache Superset Improper Input Validation vulnerability | Medium6.5 | No fix yet |
| Sep 62023 | Apache Superset Server Side Request Forgery vulnerability | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset has improper default REST API permission for Gamma users | Medium5.4 | No fix yet |
| Sep 62023 | Apache Superset users may incorrectly create resources using the import charts feature | Medium4.3 | No fix yet |