Apache SupersetGHSA-cxvp-3frm-3876
Apache Superset's SQL Alchemy connector vulnerable to SQL Injection
Medium5.4CVE-2022-41703 · Published Jan 16, 2023 · updated Jul 7, 2026
A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to, despite the user having the feature flag "ALLOW_ADHOC_SUBQUERY" disabled (default value). This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | <= 1.5.2 | No fix yet |
| <= 2.0.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-89
- Also known as
- BIT-superset-2022-41703, CVE-2022-41703, PYSEC-2026-780
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 162023 | Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints | High8.8 | No fix yet |
| Jan 162023 | Apache Superset is vulnerable to Cross-Site Scripting (XSS) | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset vulnerable to Cross-site Scripting | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset has Improper Access Control | Medium5.3 | No fix yet |
| Jan 162023 | Apache Superset Open Redirect vulnerability | Medium5.4 | No fix yet |
| Jan 162023 | Apache Superset vulnerable to Injection | Medium5.4 | No fix yet |