Apache SupersetGHSA-g49j-j489-3xpf
Apache Superset incorrect write permissions vulnerability
High7.7CVE-2023-49734 · Published Dec 19, 2023 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 2.1.3 | 2.1.3 |
| >= 3.0.0, < 3.0.2 | 3.0.2 |
Details and references
An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: before 2.1.3, from 3.0.0 before 3.0.2. Users are recommended to upgrade to version 3.0.2 or 2.1.3, which fixes the issue.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-863
- Also known as
- BIT-superset-2023-49734, CVE-2023-49734, PYSEC-2026-1180
- nvd.nist.gov/vuln/detail/CVE-2023-49734
- github.com/apache/superset/pull/25843
- github.com/apache/superset/commit/5198279a2ba41ab3e89bd9d7750694179d3f9fe6
- github.com/apache/superset/commit/cb6de0a9c9f505ee3f26e79ca9bfa5f3901528a0
- github.com/apache/superset
- lists.apache.org/thread/985h6ltvtbvdoysso780kkj7x744cds5
- www.openwall.com/lists/oss-security/2023/12/19/3
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 192023 | Apache Superset uncontrolled resource consumption CVE-2023-46104Medium6.5fixed in 2.1.2, 3.1.0rc1 | Medium6.5 | 2.1.2, 3.1.0rc1 |
| Dec 192023 | Apache Superset SQL injection vulnerability CVE-2023-49736Medium6.5fixed in 2.1.3, 3.0.2 | Medium6.5 | 2.1.3, 3.0.2 |
| Nov 282023 | Apache Superset - Elevation of Privilege CVE-2023-40610High7.3fixed in 2.1.2 | High7.3 | 2.1.2 |
| Nov 282023 | Apache Superset Allocation of Resources Without Limits or Throttling vulnerability CVE-2023-42504Medium6.5fixed in 3.0.0 | Medium6.5 | 3.0.0 |
| Nov 282023 | Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability CVE-2023-42505Medium4.3fixed in 3.0.0 | Medium4.3 | 3.0.0 |
| Nov 282023 | Apache Superset Open Redirect vulnerability CVE-2023-42502Medium5.4fixed in 3.0.0 | Medium5.4 | 3.0.0 |