Apache SupersetGHSA-fm4q-j8g4-c9j4
Apache Superset Improper Input Validation vulnerability
Medium6.5CVE-2023-39265 · Published Sep 6, 2023 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | <= 2.1.0 | No fix yet |
Details and references
Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database imports. This could allow for unexpected file creation on Superset webservers. Additionally, if Apache Superset is using a SQLite database for its metadata (not advised for production use) it could result in more severe vulnerabilities related to confidentiality and integrity. This vulnerability exists in Apache Superset versions up to and including 2.1.0.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-20
- Also known as
- BIT-superset-2023-39265, CVE-2023-39265, PYSEC-2026-1177
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 62023 | Apache Superset Server Side Request Forgery vulnerability CVE-2023-36388Medium4.3no fix yet | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset has improper default REST API permission for Gamma users CVE-2023-36387Medium5.4no fix yet | Medium5.4 | No fix yet |
| Sep 62023 | Apache Superset users may incorrectly create resources using the import charts feature CVE-2023-27526Medium4.3no fix yet | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset may expose internal traces on REST API endpoints CVE-2023-39264Medium4.3no fix yet | Medium4.3 | No fix yet |
| Sep 62023 | Apache Superset vulnerable to improper data authorization CVE-2023-27523Medium5.0no fix yet | Medium5.0 | No fix yet |
| Sep 62023 | Apache Superset has incorrect authorization check CVE-2023-32672Medium4.3no fix yet | Medium4.3 | No fix yet |