Skip to content
Apache SupersetGHSA-fxjg-28fm-pfxh

Apache Superset Server-Side Request Forgery vulnerability

Medium6.5CVE-2023-25504 · Published Jul 6, 2023 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 2.1.02.1.0
Details and references

A malicious actor who has been authenticated and granted specific permissions in Apache Superset may use the import dataset feature in order to conduct Server-Side Request Forgery attacks and query internal resources on behalf of the server where Superset is deployed. This vulnerability exists in Apache Superset versions up to and including 2.0.1.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-918
Also known as
BIT-superset-2023-25504, CVE-2023-25504, PYSEC-2026-1179

More Apache Superset advisories

All Apache Superset
DateAdvisory
Jul 62023Apache Superset vulnerable to Exposure of Sensitive Information
CVE-2023-30776Medium6.5fixed in 2.1.0
Sep 62023Apache Superset Server Side Request Forgery vulnerability
CVE-2023-36388Medium4.3no fix yet
Sep 62023Apache Superset has improper default REST API permission for Gamma users
CVE-2023-36387Medium5.4no fix yet
Sep 62023Apache Superset users may incorrectly create resources using the import charts feature
CVE-2023-27526Medium4.3no fix yet
Sep 62023Apache Superset may expose internal traces on REST API endpoints
CVE-2023-39264Medium4.3no fix yet
Sep 62023Apache Superset vulnerable to improper data authorization
CVE-2023-27523Medium5.0no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.