Skip to content
Apache SupersetGHSA-fxjm-wvj9-9c39

Information disclosure in Apache Superset

Medium6.5CVE-2020-1932 · Published Feb 26, 2020 · updated Feb 5, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
>= 0.34.0, < 0.35.20.35.2
Details and references

An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200
Also known as
BIT-superset-2020-1932, CVE-2020-1932, PYSEC-2020-224

More Apache Superset advisories

All Apache Superset
DateAdvisory
Feb 262020Users can view database names in Apache Superset
CVE-2019-12414Medium5.3fixed in 0.32.0
Feb 262020Users able to query database metadata in Apache Superset
CVE-2019-12413Medium5.3fixed in 0.31.0
Apr 302021Plaintext password leak in Apache Superset
CVE-2020-13952High8.1fixed in 0.37.2
Oct 62021Open Redirect in Apache Superset
CVE-2021-28125Medium6.1fixed in 1.1.0
Feb 22022Insufficiently Protected Credentials in Apache Superset
CVE-2021-44451High6.5fixed in 1.4.0
Apr 142022SQL injection in apache-superset
CVE-2022-27479Critical9.8fixed in 1.4.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.