Apache SupersetGHSA-fgpw-4w69-j256
Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Medium4.3CVE-2023-42505 · Published Nov 28, 2023 · updated Jul 7, 2026
An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 3.0.0 | 3.0.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- BIT-superset-2023-42505, CVE-2023-42505, PYSEC-2026-1174
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 192023 | Apache Superset SQL injection vulnerability | Medium6.5 | 2.1.3+1 more |
| Nov 282023 | Apache Superset - Elevation of Privilege | High7.3 | 2.1.2 |
| Nov 282023 | Apache Superset Allocation of Resources Without Limits or Throttling vulnerability | Medium6.5 | 3.0.0 |
| Nov 282023 | Apache Superset Open Redirect vulnerability | Medium5.4 | 3.0.0 |
| Nov 272023 | Apache Superset has Incorrect Default Permissions | Medium4.3 | 2.1.2 |
| Nov 272023 | Apache Superset Cross-site Scripting vulnerability | Medium4.3 | 2.1.2 |