Skip to content
Apache SupersetGHSA-fgpw-4w69-j256

Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Medium4.3CVE-2023-42505 · Published Nov 28, 2023 · updated Jul 7, 2026

An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 3.0.03.0.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200
Also known as
BIT-superset-2023-42505, CVE-2023-42505, PYSEC-2026-1174

More Apache Superset advisories

All Apache Superset
Advisory
Apache Superset SQL injection vulnerability
Medium6.5Dec 19, 2023
Apache Superset - Elevation of Privilege
High7.3Nov 28, 2023
Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
Medium6.5Nov 28, 2023
Apache Superset Open Redirect vulnerability
Medium5.4Nov 28, 2023
Apache Superset has Incorrect Default Permissions
Medium4.3Nov 27, 2023
Apache Superset Cross-site Scripting vulnerability
Medium4.3Nov 27, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.